PT-2022-1411 · Polkit+10 · Polkit+10
CVE-2021-4034
·
Published
2022-01-25
·
Updated
2026-09-10
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
polkit (affected versions not specified)
policykit-1 versions prior to 0.105-25+deb10u1
policykit-1 versions prior to 0.105-31+deb11u1
policykit-1 versions prior to 0.105-4ubuntu3.14.04.6+esm1
Description
A local privilege escalation issue exists in the
pkexec utility of polkit. The pkexec application is a setuid tool that allows unprivileged users to execute commands as privileged users based on predefined policies. The utility fails to correctly handle the count of calling parameters, which can lead to an out-of-bounds write and cause the application to execute environment variables as commands. A local attacker can exploit this by crafting specific environment variables to induce pkexec to execute arbitrary code, granting the attacker administrative or root privileges on the target machine.Recommendations
Update policykit-1 to version 0.105-25+deb10u1 or later for the buster distribution.
Update policykit-1 to version 0.105-31+deb11u1 or later for the bullseye distribution.
Update policykit-1 to version 0.105-4ubuntu3.14.04.6+esm1 or later for Ubuntu 14.04 ESM and 16.04 ESM.
As a temporary workaround, consider restricting access to the
pkexec utility to minimize the risk of exploitation.Exploit
Fix
LPE
RCE
DoS
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Polkit