Security News > 2021 > June > Linux system service bug lets you get root on most modern distros

Linux system service bug lets you get root on most modern distros
2021-06-11 11:58

Unprivileged attackers can get a root shell by exploiting an authentication bypass vulnerability in the polkit auth system service installed by default on many modern Linux distributions.

The polkit local privilege escalation bug was publicly disclosed, and a fix was released on June 3, 2021.

Even though many Linux distributions haven't shipped with the vulnerable polkit version until recently, any Linux system shipping with polkit 0.113 or later installed is exposed to attacks.

"When a requesting process disconnects from dbus-daemon just before the call to polkit system bus name get creds sync starts, the process cannot get a unique uid and pid of the process and it cannot verify the privileges of the requesting process," Red Hat's security advisory explains.

Linux users: please upgrade polkit to get the fix for CVE-2021-3560.

The flaws also allow local attackers with basic user privileges to gain root privileges on unpatched Linux systems.


News URL

https://www.bleepingcomputer.com/news/security/linux-system-service-bug-lets-you-get-root-on-most-modern-distros/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2022-02-16 CVE-2021-3560 Improper Check for Unusual or Exceptional Conditions vulnerability in multiple products
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user.
7.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 18 382 1424 1122 696 3624