GLSA 202201-01: Polkit: Local privilege escalation

Severity:high
Title:Polkit: Local privilege escalation
Date:01/27/2022
Bugs: #832057
ID:202201-01

Synopsis

A vulnerability in polkit could lead to local root privilege escalation.

Background

polkit is a toolkit for managing policies related to unprivileged processes communicating with privileged process.

Affected packages

Package Vulnerable Unaffected Architecture(s)
sys-auth/polkit < 0.120-r2 >= 0.120-r2 All supported architectures

Description

Flawed input validation of arguments was discovered in the 'pkexec' program's main() function.

Impact

A local attacker could achieve root privilege escalation.

Workaround

Run the following command as root: # chmod 0755 /usr/bin/pkexec

Resolution

Upgrade Polkit to a patched version.

			emerge --ask --verbose ">=sys-auth/polkit-0.120-r2"
		

References

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-202201-01.xml

Concerns?

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

License

Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.

Thank you!