Your submission was sent successfully! Close

CVE-2021-4115

Published: 14 February 2022

There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned

Notes

AuthorNote
mdeslaur
Introduced by backported patch in focal+:
PolkitSystemBusName-Retrieve-both-pid-and-uid.patch
Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
policykit-1
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(code not present)
focal
Released (0.105-26ubuntu1.3)
impish
Released (0.105-31ubuntu0.2)
jammy Not vulnerable
(0.105-32)
trusty Not vulnerable
(code not present)
upstream Needs triage

xenial Not vulnerable
(code not present)
Patches:
upstream: https://github.com/freedesktop/polkit/commit/41cb093f554da8772362654a128a84dd8a5542a7