PT-2025-11509 · Zincati · Zincati
Published
2025-03-17
·
Updated
2025-03-17
·
CVE-2025-27512
CVSS v4.0
2.1
Low
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
Zincati versions 0.0.24 through 0.0.29
Description
The issue is related to a logic error in a polkit rule shipped with Zincati, which allows any unprivileged user to deploy updates to the system and reboot into the deployed update. This means that an unprivileged user with access to the system D-Bus socket can deploy older Fedora CoreOS versions, potentially introducing known vulnerabilities. The impact is primarily on users running untrusted workloads with access to the system D-Bus socket. Note that containers do not have access to the system D-Bus socket by default.
Recommendations
For Zincati versions 0.0.24 through 0.0.29, update to version 0.0.30 to fix the logic error in the polkit rule.
As a temporary workaround for versions 0.0.24 through 0.0.29, manually add a polkit rule as described in the GitHub Security Advisory.
Exploit
Fix
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zincati