EUVD-2021-26871
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 12 May 2023. Evidence sources: cisa_kev.
- ENISA score
- 7.8 · CVSS 3.1
- Advisory evidence
- 12 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_redhat · RHSA-2021:2238Red Hat Security Advisory: polkit security update
- csaf_redhat · RHSA-2021:2555Red Hat Security Advisory: OpenShift Container Platform 4.7.19 packages and security update
- csaf_opensuse · openSUSE-SU-2021:0838-1Security update for polkit
- csaf_suse · SUSE-SU-2021:1842-1Security update for polkit
- csaf_redhat · RHSA-2021:2522Red Hat Security Advisory: Red Hat Virtualization Host security update [ovirt-4.4.6]
- csaf_redhat · RHSA-2021:2236Red Hat Security Advisory: polkit security update
- csaf_redhat · RHSA-2021:2237Red Hat Security Advisory: polkit security update
- csaf_opensuse · openSUSE-SU-2021:1843-1Security update for polkit
- csaf_suse · SUSE-SU-2021:1843-1Security update for polkit
- csaf_suse · SUSE-SU-2021:1844-1Security update for polkit
