CVE-2021-4115
published 2022-02-21CVE-2021-4115: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.53%
41.2th percentile
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | policykit-1 | < policykit-1 0.105-32 (bookworm) | policykit-1 0.105-32 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| polkit_project | polkit | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PolicyKit vulnerability
vendor_ubuntu·2022-02-28
CVE-2021-4115 PolicyKit vulnerability
Title: PolicyKit vulnerability
Summary: policykit-1 could be made to crash if it received specially crafted data.
Kevin Backhouse discovered that PolicyKit incorrectly handled file
descriptors. A local attacker could possibly use this issue to cause
PolicyKit to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
polkit: file descriptor leak allows an unprivileged user to cause a crash
vendor_redhat·2022-02-14·CVSS 5.5
CVE-2021-4115 [MEDIUM] CWE-403 polkit: file descriptor leak allows an unprivileged user to cause a crash
polkit: file descriptor leak allows an unprivileged user to cause a crash
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion.
The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned.
Package: polkit (Red Hat Enterprise Linux 6) - Not affected
Package: polkit (Red Hat Enterprise Linux 7) - Not af
Debian
CVE-2021-4115: policykit-1 - There is a flaw in polkit which can allow an unprivileged user to cause polkit t...
vendor_debian·2021·CVSS 5.5
CVE-2021-4115 [MEDIUM] CVE-2021-4115: policykit-1 - There is a flaw in polkit which can allow an unprivileged user to cause polkit t...
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
Scope: local
bookworm: resolved (fixed in 0.105-32)
bullseye: open
forky: resolved (fixed in 0.105-32)
sid: resolved (fixed in 0.105-32)
trixie: resolved (fixed in 0.105-32)
GHSA
GHSA-vvr6-r92h-x7jw: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion
ghsa_unreviewed·2022-02-22
CVE-2021-4115 [MEDIUM] CWE-400 GHSA-vvr6-r92h-x7jw: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
OSV
CVE-2021-4115: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion
osv·2022-02-21·CVSS 5.5
CVE-2021-4115 [MEDIUM] CVE-2021-4115: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/172849/polkit-File-Descriptor-Exhaustion.htmlhttps://access.redhat.com/security/cve/cve-2021-4115https://gitlab.com/redhat/centos-stream/rpms/polkit/-/merge_requests/6/diffs?commit_id=bf900df04dc390d389e59aa10942b0f2b15c531ehttps://gitlab.freedesktop.org/polkit/polkit/-/issues/141https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VGKWCBS6IDZYYDYM2WIWJM5BL7QQTWPF/https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://packetstormsecurity.com/files/172849/polkit-File-Descriptor-Exhaustion.htmlhttps://access.redhat.com/security/cve/cve-2021-4115https://gitlab.com/redhat/centos-stream/rpms/polkit/-/merge_requests/6/diffs?commit_id=bf900df04dc390d389e59aa10942b0f2b15c531ehttps://gitlab.freedesktop.org/polkit/polkit/-/issues/141https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VGKWCBS6IDZYYDYM2WIWJM5BL7QQTWPF/https://www.oracle.com/security-alerts/cpujul2022.html
2022-02-21
Published