REDHAT-BUG-1245673: Medium severity polkit vulnerability
It was reported that if polkit, while reading action descriptions from /usr/share/polkit-1/actions, encounters a duplicate action ID, it corrupts the heap. The effects of corruption are e.g. visible on stderr as frequent use of unrelated strings when running polkit without --no-debug.
Presumably a local attacker might be able to manipulate polkit’s heap enough to achieve privilege escalation through this.
Upstream bug: https://bugs.freedesktop.org/showbug.cgi?id=83590 Upstream patch is attached.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1245673?
The severity of REDHAT-BUG-1245673 is currently undetermined but is related to heap corruption, which can lead to instability in polkit.
How do I fix REDHAT-BUG-1245673?
Fixing REDHAT-BUG-1245673 involves ensuring that there are no duplicate action IDs in the polkit action descriptions.
What are the symptoms of REDHAT-BUG-1245673?
Symptoms of REDHAT-BUG-1245673 include heap corruption, which may manifest as unrelated strings appearing in stderr when polkit is run.
Which software is affected by REDHAT-BUG-1245673?
REDHAT-BUG-1245673 affects the polkit software developed by FreeDesktop.
Can REDHAT-BUG-1245673 lead to system vulnerabilities?
Yes, REDHAT-BUG-1245673 can potentially lead to system vulnerabilities due to its impact on heap memory integrity.