PT-2022-1926 · Polkit+10 · Polkit+10

Published

2020-09-11

·

Updated

2024-06-15

·

CVE-2021-4115

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions polkit (affected versions not specified)
Description The issue is related to a flaw in polkit that can allow an unprivileged user to cause polkit to crash due to process file descriptor exhaustion. This can lead to a denial of service. The threat from this issue is primarily to availability. The duration of the polkit process outage is tied to the failing process being reaped and a new one being spawned.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1546
ALT-PU-2020-2764
ALT-PU-2022-1390
ALT-PU-2022-1606
ALT-PU-2022-1832
BDU:2022-01462
CESA-2022_1546
CVE-2021-4115
MGASA-2022-0080
OESA-2022-1572
OPENSUSE-SU-2022:0525-1
OPENSUSE-SU-2022_0525-1
OPENSUSE-SU-2024:11868-1
RHSA-2022:1546
RHSA-2022_1546
RLSA-2022:1546
SUSE-SU-2022:0524-1
SUSE-SU-2022:0525-1
SUSE-SU-2022:0525-2
SUSE-SU-2022_0524-1
SUSE-SU-2022_0525-1
SUSE-SU-2022_0525-2
USN-5304-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Polkit