CVE-2015-4625: Fedoraproject Fedora
Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.
Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.
Affected products
- Fedoraproject Fedora: version 21 only; version 22 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Polkit Project Polkit: up to and including 0.112
Published 2015-10-26. Last modified 2026-06-17.