REDHAT-BUG-1655925: Medium severity polkit vulnerability
It was found that creating a user of group above INT32MAX would wrap around the numeric uid or gid. Polkit is not able to handle this properly, resulting in an authentication bypass.
References:
https://seclists.org/oss-sec/2018/q4/198
Upstream issue:
https://gitlab.freedesktop.org/polkit/polkit/issues/74
Proposed patch:
https://gitlab.freedesktop.org/zbyszek/polkit/commit/fbaab32cb4ed9ed5f1e3eea6cd317d443aa427dc
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1655925?
The severity of REDHAT-BUG-1655925 is considered high due to the potential for an authentication bypass.
How does REDHAT-BUG-1655925 affect Polkit?
REDHAT-BUG-1655925 affects Polkit by allowing user creation with group IDs above INT32_MAX, leading to numeric wraparound and improper handling.
What systems are impacted by REDHAT-BUG-1655925?
REDHAT-BUG-1655925 impacts systems using Polkit for user authentication management.
How do I fix REDHAT-BUG-1655925?
To fix REDHAT-BUG-1655925, update Polkit to the latest patched version that resolves the user and group ID handling issue.
What should I do if I'm affected by REDHAT-BUG-1655925?
If affected by REDHAT-BUG-1655925, it's essential to apply the relevant security updates and monitor for any unusual authentication behavior.