Polkit Vulnerability Affecting Unprivileged User Access
CVE-2021-4115

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 February 2022

What is CVE-2021-4115?

This vulnerability in polkit can be exploited by an unprivileged user to cause the polkit service to become unresponsive, leading to potential system outages. The exploit is facilitated through process file descriptor exhaustion, which affects the availability of the service. The duration of the service outage is contingent on the proper management of failing processes and the successful spawning of new ones. It is crucial for system administrators to be aware of this vulnerability and apply appropriate measures to mitigate the risks associated with it.

Affected Version(s)

polkitd 0.117

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.