PT-2025-11509 · Zincati · Zincati

Published

2025-03-17

·

Updated

2025-03-17

·

CVE-2025-27512

CVSS v4.0

2.1

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Zincati versions 0.0.24 through 0.0.29
Description The issue is related to a logic error in a polkit rule shipped with Zincati, which allows any unprivileged user to deploy updates to the system and reboot into the deployed update. This means that an unprivileged user with access to the system D-Bus socket can deploy older Fedora CoreOS versions, potentially introducing known vulnerabilities. The impact is primarily on users running untrusted workloads with access to the system D-Bus socket. Note that containers do not have access to the system D-Bus socket by default.
Recommendations For Zincati versions 0.0.24 through 0.0.29, update to version 0.0.30 to fix the logic error in the polkit rule. As a temporary workaround for versions 0.0.24 through 0.0.29, manually add a polkit rule as described in the GitHub Security Advisory.

Exploit

Fix

LPE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00116
CVE-2025-27512
GHSA-W6FV-6GCC-X825

Affected Products

Zincati