PT-2022-1411 · Polkit+10 · Polkit+10

CVE-2021-4034

·

Published

2022-01-25

·

Updated

2026-09-10

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions polkit (affected versions not specified) policykit-1 versions prior to 0.105-25+deb10u1 policykit-1 versions prior to 0.105-31+deb11u1 policykit-1 versions prior to 0.105-4ubuntu3.14.04.6+esm1
Description A local privilege escalation issue exists in the pkexec utility of polkit. The pkexec application is a setuid tool that allows unprivileged users to execute commands as privileged users based on predefined policies. The utility fails to correctly handle the count of calling parameters, which can lead to an out-of-bounds write and cause the application to execute environment variables as commands. A local attacker can exploit this by crafting specific environment variables to induce pkexec to execute arbitrary code, granting the attacker administrative or root privileges on the target machine.
Recommendations Update policykit-1 to version 0.105-25+deb10u1 or later for the buster distribution. Update policykit-1 to version 0.105-31+deb11u1 or later for the bullseye distribution. Update policykit-1 to version 0.105-4ubuntu3.14.04.6+esm1 or later for Ubuntu 14.04 ESM and 16.04 ESM. As a temporary workaround, consider restricting access to the pkexec utility to minimize the risk of exploitation.

Exploit

Fix

LPE

RCE

DoS

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:0267
ALSA-2022_0267
ALSA-2025_16880
ALT-PU-2022-1139
ALT-PU-2022-1140
ALT-PU-2022-1174
ALT-PU-2022-1190
ALT-PU-2022-1346
ALT-PU-2022-1678
ALT-PU-2022-1679
ALT-PU-2022-1680
ALT-PU-2022-1688
ALT-PU-2022-1811
AZL-8335
BDU:2022-00488
CESA-2022_0267
CESA-2022_0274
CVE-2021-4034
DLA-2899-1
DSA-5059-1
ELSA-2022-0267
ELSA-2022-0274
ELSA-2022-9073
MGASA-2022-0037
OESA-2022-1502
OPENSUSE-SU-2022:0190-1
OPENSUSE-SU-2022_0190-1
OPENSUSE-SU-2024:11780-1
RHSA-2022:0265
RHSA-2022:0266
RHSA-2022:0267
RHSA-2022:0268
RHSA-2022:0269
RHSA-2022:0270
RHSA-2022:0271
RHSA-2022:0272
RHSA-2022:0273
RHSA-2022:0274
RHSA-2022:0443
RHSA-2022:0540
RHSA-2022_0267
RHSA-2022_0269
RHSA-2022_0274
RLSA-2022:0267
RLSA-2022_0267
ROSA-SA-2022-2012
ROSA-SA-2022-2013
SUSE-SU-2022:0189-1
SUSE-SU-2022:0190-1
SUSE-SU-2022:0191-1
SUSE-SU-2022_0189-1
SUSE-SU-2022_0190-1
SUSE-SU-2022_0191-1
USN-5252-1
USN-5252-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Polkit