Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libvirtUpgrade polkitUpgrade spice-gtk. | Aug 30, 2017 | Oct 3, 2013 |
| Centos_linux | — | Upgrade polkitUpgrade polkit-desktop-policyUpgrade polkit-docsUpgrade polkit-devel | Dec 1, 2016 | Oct 3, 2013 |
| Debian | — | Upgrade policykit-1 | Jul 30, 2024 | Oct 3, 2013 |
| Gentoo Linux | — | Upgrade net-misc/spice-gtk.Upgrade sys-auth/polkit.Upgrade sys-apps/systemd.Upgrade app-emulation/libvirt.Upgrade net-print/hplip. | Oct 30, 2017 | Oct 3, 2013 |
| Oracle Solaris | — | Upgrade system/library/polkit to version 0.113-11.4.9.0.1.1.0 on Solaris 11.4Upgrade library/desktop/webkitgtk4 to version 2.22.6-11.4.9.0.1.1.0 on Solaris 11.4 | May 30, 2019 | Oct 3, 2013 |
| Oracle_linux | — | Upgrade polkitUpgrade polkit-desktop-policyUpgrade polkit-docsUpgrade polkit-devel | Oct 16, 2024 | Oct 3, 2013 |
| Suse | — | Upgrade libgudev-1_0-0-32bitUpgrade hplip-saneUpgrade libudev-mini1Upgrade systemd-mini-develUpgrade systemdUpgrade libudev1-32bitUpgrade systemd-sysvinitUpgrade libudev-mini-develUpgrade systemd-miniUpgrade libudev-develUpgrade udev-miniUpgrade systemd-32bitUpgrade hplip-hpijsUpgrade typelib-1_0-GUdev-1_0Upgrade systemd-mini-sysvinitUpgrade systemd-develUpgrade hplipUpgrade libudev1Upgrade systemd-loggerUpgrade udevUpgrade systemd-analyzeUpgrade systemd-mini-analyzeUpgrade systemd-gtkUpgrade libgudev-1_0-0Upgrade libgudev-1_0-devel | Dec 12, 2013 | Oct 3, 2013 |
| Ubuntu | — | Upgrade policykit-1 | Nov 8, 2024 | Oct 3, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub