PT-2022-1411 · Polkit+10 · Polkit+10

Published

2022-01-25

·

Updated

2026-06-17

·

CVE-2021-4034

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions polkit versions prior to 0.105-25+deb10u1 polkit versions prior to 0.105-31+deb11u1 policykit-1 versions prior to 0.105-4ubuntu3.14.04.6+esm1
Description A local privilege escalation issue exists in the pkexec utility of polkit. The pkexec application is a setuid tool that allows unprivileged users to execute commands as privileged users based on predefined policies. The utility fails to correctly handle the count of calling parameters, which can lead to an out-of-bounds write when processing command-line arguments. This memory corruption allows an attacker to induce pkexec to execute environment variables as commands, enabling the execution of arbitrary code. Successful exploitation grants an unprivileged local user administrative or root privileges on the target machine.
Recommendations Update policykit-1 packages to version 0.105-25+deb10u1 or later. Update policykit-1 packages to version 0.105-31+deb11u1 or later. Update libpolkit-backend-1-0, policykit-1-doc, libpolkit-agent-1-0, libpolkit-gobject-1-dev, libpolkit-gobject-1-0, policykit-1, gir1.2-polkit-1.0, libpolkit-backend-1-dev, and libpolkit-agent-1-dev to version 0.105-4ubuntu3.14.04.6+esm1 or later.

Exploit

Fix

DoS

RCE

LPE

Memory Corruption

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:0267
ALSA-2022_0267
ALSA-2025_16880
ALT-PU-2022-1139
ALT-PU-2022-1140
ALT-PU-2022-1174
ALT-PU-2022-1190
ALT-PU-2022-1346
ALT-PU-2022-1678
ALT-PU-2022-1679
ALT-PU-2022-1680
ALT-PU-2022-1688
ALT-PU-2022-1811
AZL-8335
BDU:2022-00488
CESA-2022_0267
CESA-2022_0274
CVE-2021-4034
DLA-2899-1
DSA-5059-1
ELSA-2022-0267
ELSA-2022-0274
ELSA-2022-9073
MGASA-2022-0037
OESA-2022-1502
OPENSUSE-SU-2022:0190-1
OPENSUSE-SU-2022_0190-1
OPENSUSE-SU-2024:11780-1
RHSA-2022:0265
RHSA-2022:0266
RHSA-2022:0267
RHSA-2022:0268
RHSA-2022:0269
RHSA-2022:0270
RHSA-2022:0271
RHSA-2022:0272
RHSA-2022:0273
RHSA-2022:0274
RHSA-2022:0443
RHSA-2022:0540
RHSA-2022_0267
RHSA-2022_0269
RHSA-2022_0274
RLSA-2022:0267
RLSA-2022_0267
ROSA-SA-2022-2012
ROSA-SA-2022-2013
SUSE-SU-2022:0189-1
SUSE-SU-2022:0190-1
SUSE-SU-2022:0191-1
SUSE-SU-2022_0189-1
SUSE-SU-2022_0190-1
SUSE-SU-2022_0191-1
USN-5252-1
USN-5252-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Polkit