[security/bug] Major Bug Grants Root For All Major Linux Distributions
3 messages · started by Devi Garcia on Jan 27, 2022
[security/bug] Major Bug Grants Root For All Major Linux Distributions
From Devi Garcia · Jan 27, 2022
The exploit is a memory corruption vulnerability in Polkit, a framework
that handles the privilege level of various system processes. It
specifically impacts the program pkexec. With the proof-of-concept exploit
(file download warning) in hand, all an attacker needs to do to
escalate themselves to root is to compile the program on the computer
and run it as the default user.
As bad as this sounds, it seems as though all of the major distributions
that this impacts have already released updates that patch the issue,
including Debian, Ubuntu, Red Hat, Fedora, open SUSE, and Arch

[security/bug] Major Bug Grants Root For All Major Linux Distributions
From Devi Garcia · Jan 27, 2022
The exploit is a memory corruption vulnerability in Polkit, a framework
that handles the privilege level of various system processes. It
specifically impacts the program pkexec. With the proof-of-concept exploit
(file download warning) in hand, all an attacker needs to do to
escalate themselves to root is to compile the program on the computer
and run it as the default user.
As bad as this sounds, it seems as though all of the major distributions
that this impacts have already released updates that patch the issue,
including Debian, Ubuntu, Red Hat, Fedora, open SUSE, and Arch

Re: [security/bug] Major Bug Grants Root For All Major Linux Distributions
From Teruel deCampo MD · Jan 27, 2022
Devi,
Thank you very much for this posting. I run OpenSuse leap 15.3 and I
have setup the updates once a week, instead of daily, however in
situation like this one, as soon as I read the article I setup the
update and yes a new version of Polkit was ready and the system is
updated. Thank you again for this very useful info. -=teruel=- On Thu, 2022-01-27 at 17:36 +0000, Devi Garcia wrote:
Quoted reply (3 lines)
--------------------------------------------------------------------
Cochise Linux Users Group Mailing List - cochiselinux@freelists.org
For more information: https://cochiselinuxusergroup.org/
Mailing List Archive: https://www.freelists.org/archive/cochiselinux
To unsubscribe: //www.freelists.org/list/cochiselinux
have setup the updates once a week, instead of daily, however in
situation like this one, as soon as I read the article I setup the
update and yes a new version of Polkit was ready and the system is
updated. Thank you again for this very useful info. -=teruel=- On Thu, 2022-01-27 at 17:36 +0000, Devi Garcia wrote:
Quoted reply (3 lines)
The exploit is a memory corruption vulnerability in Polkit,
The exploit is a memory corruption vulnerability in Polkit,
Cochise Linux Users Group Mailing List - cochiselinux@freelists.org
For more information: https://cochiselinuxusergroup.org/
Mailing List Archive: https://www.freelists.org/archive/cochiselinux
To unsubscribe: //www.freelists.org/list/cochiselinux