GLSA 202201-01: Polkit: Local privilege escalation
Severity: | high |
Title: | Polkit: Local privilege escalation |
Date: | 01/27/2022 |
Bugs: |
|
ID: | 202201-01 |
Synopsis
A vulnerability in polkit could lead to local root privilege escalation.Background
polkit is a toolkit for managing policies related to unprivileged processes communicating with privileged process.
Affected packages
Package | Vulnerable | Unaffected | Architecture(s) |
---|---|---|---|
sys-auth/polkit | < 0.120-r2 | >= 0.120-r2 | All supported architectures |
Description
Flawed input validation of arguments was discovered in the 'pkexec' program's main() function.
Impact
A local attacker could achieve root privilege escalation.
Workaround
Run the following command as root: # chmod 0755 /usr/bin/pkexec
Resolution
Upgrade Polkit to a patched version.
emerge --ask --verbose ">=sys-auth/polkit-0.120-r2"
References
Availability
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.
License
Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.