Vulnerability in Polkit allows privilege escalation in the system

A vulnerability (CVE-2021-3560) has been identified in the Polkit component used in distributions for allowing unprivileged users to perform actions that require elevated access rights (such as mounting USB drives), enabling a local user to gain root privileges on the system. The vulnerability has been fixed in Polkit version 0.119.

The issue first appeared starting with release 0.113, but many distributions, including RHEL, Ubuntu, Debian, and SUSE, backported the vulnerable functionality into packages based on older releases of Polkit (package fixes are already available in the distributions).

The problem occurs in the polkit_system_bus_name_get_creds_sync() function, which retrieves the identifiers (uid and pid) of the process requesting privilege escalation. Polkit identifies the process through a unique name assigned in DBus, which is then used for privilege verification. If the process disconnects from the dbus-daemon just before the polkit_system_bus_name_get_creds_sync handler is invoked, the handler receives an error code instead of the unique name.

The vulnerability arises because the returned error code is not handled properly and the polkit_system_bus_name_get_creds_sync() function returns TRUE instead of FALSE, even though it failed to match the process with uid/pid and verify the privileges requested for the process. The code that invoked the polkit_system_bus_name_get_creds_sync() function assumes that the check was successful and the privilege escalation request came from root, not from an unprivileged user, allowing privileged actions to be executed without additional authentication and authorization confirmation.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster