CVE-2019-6133
published 2019-01-11CVE-2019-6133: In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are…
PriorityP425medium6.7CVSS 3.0
AVLACHPRLUIRSUCHIHAH
EPSS
0.45%
36.1th percentile
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 4.19.16-1 (bookworm) | linux 4.19.16-1 (bookworm) |
| debian | policykit-1 | < linux 4.19.16-1 (bookworm) | linux 4.19.16-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.19.16-1 | 4.19.16-1 |
| linux | linux_kernel | >= 0 < 4.19.16-1 | 4.19.16-1 |
| linux | linux_kernel | >= 0 < 4.19.16-1 | 4.19.16-1 |
| linux | linux_kernel | >= 0 < 4.19.16-1 | 4.19.16-1 |
| linux | linux_kernel | >= 0 < 4.4.0-143.169 | 4.4.0-143.169 |
| linux | linux_kernel | >= 0 < 4.15.0-46.49 | 4.15.0-46.49 |
| polkit_project | polkit | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PolicyKit vulnerability
vendor_ubuntu·2019-09-02
CVE-2019-6133 PolicyKit vulnerability
Title: PolicyKit vulnerability
Summary: PolicyKit could allow unintended access.
USN-3934-1 fixed a vulnerability in Policykit. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that PolicyKit incorrectly relied on the fork() system
call in the Linux kernel being atomic. A local attacker could possibly use
this issue to gain access to services that have cached authorizations.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
PolicyKit vulnerability
vendor_ubuntu·2019-04-03
CVE-2019-6133 PolicyKit vulnerability
Title: PolicyKit vulnerability
Summary: PolicyKit could allow unintended access.
It was discovered that PolicyKit incorrectly relied on the fork() system
call in the Linux kernel being atomic. A local attacker could possibly use
this issue to gain access to services that have cached authorizations.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Linux kernel (Xenial HWE) vulnerabilities
vendor_ubuntu·2019-03-15·CVSS 5.5
CVE-2017-18241 [MEDIUM] Linux kernel (Xenial HWE) vulnerabilities
Title: Linux kernel (Xenial HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3910-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the f2fs filesystem implementation in the Linux
kernel did not handle the noflush_merge mount option correctly. An attacker
could use this to cause a denial of service (system crash).
(CVE-2017-18241)
It was discovered that the procfs filesystem did not properly handle
processes mapping some memory elements onto files. A local attacker could
use this to block utilities that examine the procfs filesystem to report
operating system state, such
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-03-15·CVSS 5.5
CVE-2017-18241 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the f2fs filesystem implementation in the Linux
kernel did not handle the noflush_merge mount option correctly. An attacker
could use this to cause a denial of service (system crash).
(CVE-2017-18241)
It was discovered that the procfs filesystem did not properly handle
processes mapping some memory elements onto files. A local attacker could
use this to block utilities that examine the procfs filesystem to report
operating system state, such as ps(1). (CVE-2018-1120)
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use t
Ubuntu
Linux kernel (Trusty HWE) vulnerability
vendor_ubuntu·2019-03-13
CVE-2019-6133 Linux kernel (Trusty HWE) vulnerability
Title: Linux kernel (Trusty HWE) vulnerability
Summary: The system could be made to run programs as an administrator.
USN-3908-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
Jann Horn discovered a race condition in the fork() system call in the
Linux kernel. A local attacker could use this to gain access to services
that cache authorizations.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules yo
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2019-03-12
CVE-2019-6133 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
Jann Horn discovered a race condition in the fork() system call in the
Linux kernel. A local attacker could use this to gain access to services
that cache authorizations.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this a
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-03-06·CVSS 7.0
CVE-2018-16880 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3903-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 18.10 for Ubuntu 18.04 LTS.
Jason Wang discovered that the vhost net driver in the Linux kernel
contained an out of bounds write vulnerability. An attacker in a guest
virtual machine could use this to cause a denial of service (host system
crash) or possibly execute arbitrary code in the host kernel.
(CVE-2018-16880)
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-20
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-03-06·CVSS 7.0
CVE-2018-16880 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jason Wang discovered that the vhost net driver in the Linux kernel
contained an out of bounds write vulnerability. An attacker in a guest
virtual machine could use this to cause a denial of service (host system
crash) or possibly execute arbitrary code in the host kernel.
(CVE-2018-16880)
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
Jann Horn discovered a race condition in the fork() system call in the
Linux kernel. A local attacker could use this to gain access to services
that cache authorizations. (CVE-2019-6133)
Instructions:
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in
the Linux kernel. A local attacker could use this to gain access to
services that cache authorizations. (CVE-2019-6133)
Instructions: After a standard system update you need to reboot your computer to
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3901-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the for
Red Hat
polkit: Temporary auth hijacking via PID reuse and non-atomic fork
vendor_redhat·2019-01-09·CVSS 6.7
CVE-2019-6133 [MEDIUM] CWE-697 polkit: Temporary auth hijacking via PID reuse and non-atomic fork
polkit: Temporary auth hijacking via PID reuse and non-atomic fork
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
A vulnerability was found in polkit. When authentication is performed by a non-root user to perform an administrative task, the authentication is temporarily cached in such a way that a local attacker could impersonate the authorized process, thus gaining access to elevated privileges.
Package: polkit (Red Hat Enterprise Linux 8) - Not affected
Package: rhvm-appliance (Red Hat Virtualization 4) - Will not fix
Debian
CVE-2019-6133: linux - In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be by...
vendor_debian·2019·CVSS 6.7
CVE-2019-6133 [MEDIUM] CVE-2019-6133: linux - In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be by...
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
Scope: local
bookworm: resolved (fixed in 4.19.16-1)
bullseye: resolved (fixed in 4.19.16-1)
forky: resolved (fixed in 4.19.16-1)
sid: resolved (fixed in 4.19.16-1)
trixie: resolved (fixed in 4.19.16-1)
GHSA
GHSA-7j6c-jrh9-mvqm: In PolicyKit (aka polkit) 0
ghsa_unreviewed·2022-05-13
CVE-2019-6133 [MEDIUM] CWE-362 GHSA-7j6c-jrh9-mvqm: In PolicyKit (aka polkit) 0
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2019-03-15·CVSS 5.5
CVE-2017-18241 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the f2fs filesystem implementation in the Linux
kernel did not handle the noflush_merge mount option correctly. An attacker
could use this to cause a denial of service (system crash).
(CVE-2017-18241)
It was discovered that the procfs filesystem did not properly handle
processes mapping some memory elements onto files. A local attacker could
use this to block utilities that examine the procfs filesystem to report
operating system state, such as ps(1). (CVE-2018-1120)
Hui Peng and Mathias Payer discovered that the Option USB High Speed driver
in the Linux kernel did not properly validate metadata received from the
device. A physically proximate attacker could use this to cause a denial of
s
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2019-03-15·CVSS 5.5
CVE-2017-18241 [MEDIUM] linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3910-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
It was discovered that the f2fs filesystem implementation in the Linux
kernel did not handle the noflush_merge mount option correctly. An attacker
could use this to cause a denial of service (system crash).
(CVE-2017-18241)
It was discovered that the procfs filesystem did not properly handle
processes mapping some memory elements onto files. A local attacker could
use this to block utilities that examine the procfs filesystem to report
operating system state, such as ps(1). (CVE-2018-1120)
Hui Peng and Mathias Payer discovered that t
OSV
linux-hwe, linux-azure vulnerabilities
osv·2019-03-06·CVSS 7.0
[HIGH] linux-hwe, linux-azure vulnerabilities
linux-hwe, linux-azure vulnerabilities
USN-3903-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 18.10 for Ubuntu 18.04 LTS.
Jason Wang discovered that the vhost net driver in the Linux kernel
contained an out of bounds write vulnerability. An attacker in a guest
virtual machine could use this to cause a denial of service (host system
crash) or possibly execute arbitrary code in the host kernel.
(CVE-2018-16880)
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
Jann Horn discovered a race condition in the fork() system
OSV
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
osv·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
linux-hwe, linux-aws-hwe, linux-azure, linux-gcp, linux-oracle vulnerabilities
USN-3901-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in the
Linux
OSV
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
osv·2019-03-05·CVSS 5.5
CVE-2018-18397 [MEDIUM] linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
linux, linux-aws, linux-gcp, linux-kvm, linux-oem, linux-oracle, linux-raspi2 vulnerabilities
Jann Horn discovered that the userfaultd implementation in the Linux kernel
did not properly restrict access to certain ioctls. A local attacker could
use this possibly to modify files. (CVE-2018-18397)
It was discovered that the crypto subsystem of the Linux kernel leaked
uninitialized memory to user space in some situations. A local attacker
could use this to expose sensitive information (kernel memory).
(CVE-2018-19854)
Jann Horn discovered a race condition in the fork() system call in
the Linux kernel. A local attacker could use this to gain access to
services that cache authorizations. (CVE-2019-6133)
OSV
CVE-2019-6133: In PolicyKit (aka polkit) 0
osv·2019-01-11·CVSS 6.7
CVE-2019-6133 [MEDIUM] CVE-2019-6133: In PolicyKit (aka polkit) 0
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork [fedora-all]
bugzilla·2019-01-21·CVSS 6.7
CVE-2019-6133 [MEDIUM] CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork [fedora-all]
CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork
bugzilla·2019-01-08·CVSS 6.7
CVE-2019-6133 [MEDIUM] CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork
CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork
polkit has a vulnerability that allows a local attacker to hijack a PID during an authentication attempt by a non-root user and subsequently execute code as the authenticated process.
Upstream patch:
https://gitlab.freedesktop.org/polkit/polkit/commit/c898fdf4b1aafaa04f8ada9d73d77c8bb76e2f81
https://gitlab.freedesktop.org/polkit/polkit/merge_requests/19
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7b55851367136b1efd84d98fea81ba57a98304cf
Discussion:
Acknowledgments:
Name: Jan Rybar (freedesktop.org)
Upstream: Jann Horn (Google Project Zero)
---
External References:
https://bugs.chromium.org/p/project-zero/issues/detail?id=1692
---
Upstream bug:
https://gitlab.freede
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00049.htmlhttp://www.securityfocus.com/bid/106537https://access.redhat.com/errata/RHSA-2019:0230https://access.redhat.com/errata/RHSA-2019:0420https://access.redhat.com/errata/RHSA-2019:0832https://access.redhat.com/errata/RHSA-2019:2699https://access.redhat.com/errata/RHSA-2019:2978https://bugs.chromium.org/p/project-zero/issues/detail?id=1692https://git.kernel.org/linus/7b55851367136b1efd84d98fea81ba57a98304cfhttps://gitlab.freedesktop.org/polkit/polkit/commit/c898fdf4b1aafaa04f8ada9d73d77c8bb76e2f81https://gitlab.freedesktop.org/polkit/polkit/merge_requests/19https://lists.debian.org/debian-lts-announce/2019/01/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00041.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00042.htmlhttps://support.f5.com/csp/article/K22715344https://usn.ubuntu.com/3901-1/https://usn.ubuntu.com/3901-2/https://usn.ubuntu.com/3903-1/https://usn.ubuntu.com/3903-2/https://usn.ubuntu.com/3908-1/https://usn.ubuntu.com/3908-2/https://usn.ubuntu.com/3910-1/https://usn.ubuntu.com/3910-2/https://usn.ubuntu.com/3934-1/https://usn.ubuntu.com/3934-2/http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00049.htmlhttp://www.securityfocus.com/bid/106537https://access.redhat.com/errata/RHSA-2019:0230https://access.redhat.com/errata/RHSA-2019:0420https://access.redhat.com/errata/RHSA-2019:0832https://access.redhat.com/errata/RHSA-2019:2699https://access.redhat.com/errata/RHSA-2019:2978https://bugs.chromium.org/p/project-zero/issues/detail?id=1692https://git.kernel.org/linus/7b55851367136b1efd84d98fea81ba57a98304cfhttps://gitlab.freedesktop.org/polkit/polkit/commit/c898fdf4b1aafaa04f8ada9d73d77c8bb76e2f81https://gitlab.freedesktop.org/polkit/polkit/merge_requests/19https://lists.debian.org/debian-lts-announce/2019/01/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00041.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00042.htmlhttps://support.f5.com/csp/article/K22715344https://usn.ubuntu.com/3901-1/https://usn.ubuntu.com/3901-2/https://usn.ubuntu.com/3903-1/https://usn.ubuntu.com/3903-2/https://usn.ubuntu.com/3908-1/https://usn.ubuntu.com/3908-2/https://usn.ubuntu.com/3910-1/https://usn.ubuntu.com/3910-2/https://usn.ubuntu.com/3934-1/https://usn.ubuntu.com/3934-2/
2019-01-11
Published