Skip to content
Threat Feed
medium advisory

PolicyKit Local Denial of Service Vulnerability

A local, unprivileged attacker can exploit CVE-2024-41611 in PolicyKit to trigger a denial of service condition, potentially leading to system instability.

CVE search metadata

CVE search record: CVE-2024-41611. Severity: critical. CVSS: 9.8. EPSS: 0.78%. KEV: no. Product: PolicyKit. Brief: PolicyKit Local Denial of Service Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-08-policykit-dos/

A vulnerability has been identified in PolicyKit, the component responsible for defining and handling authorization policies in Unix-like operating systems. An unprivileged local attacker can leverage this flaw to trigger a denial of service (DoS) state. By exploiting the underlying vulnerability, identified as CVE-2024-41611, an attacker can cause the PolicyKit service to become unresponsive or crash, which may impact system-wide authorization services. This vulnerability is significant because it allows a local user to disrupt core system operations that rely on PolicyKit for privileged access management. Defensive teams should prioritize patching or applying updates provided by their Linux distribution maintainers to address this instability.

Impact

Successful exploitation results in a local denial of service. The impact includes the potential for system-wide service disruption, as many privileged operations rely on PolicyKit to validate user actions. This vulnerability affects systems where PolicyKit is active, primarily impacting Linux environments across all sectors.

Recommendation

  • Apply the security patches provided by your Linux distribution vendor to resolve CVE-2024-41611.
  • Audit system logs for unexpected terminations or restarts of the polkitd process.

Mitigations

Patch PolicyKit to the latest version provided by distribution maintainers

immediate IT Operations

CVE-2024-41611