Advisory Published
Updated

REDHAT-BUG-1655925

First published: Tue Dec 04 2018(Updated: )

It was found that creating a user of group above INT32_MAX would wrap around the numeric uid or gid. Polkit is not able to handle this properly, resulting in an authentication bypass. References: <a href="https://seclists.org/oss-sec/2018/q4/198">https://seclists.org/oss-sec/2018/q4/198</a> Upstream issue: <a href="https://gitlab.freedesktop.org/polkit/polkit/issues/74">https://gitlab.freedesktop.org/polkit/polkit/issues/74</a> Proposed patch: <a href="https://gitlab.freedesktop.org/zbyszek/polkit/commit/fbaab32cb4ed9ed5f1e3eea6cd317d443aa427dc">https://gitlab.freedesktop.org/zbyszek/polkit/commit/fbaab32cb4ed9ed5f1e3eea6cd317d443aa427dc</a>

Affected SoftwareAffected VersionHow to fix
Polkit

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-1655925?

    The severity of REDHAT-BUG-1655925 is considered high due to the potential for an authentication bypass.

  • How does REDHAT-BUG-1655925 affect Polkit?

    REDHAT-BUG-1655925 affects Polkit by allowing user creation with group IDs above INT32_MAX, leading to numeric wraparound and improper handling.

  • What systems are impacted by REDHAT-BUG-1655925?

    REDHAT-BUG-1655925 impacts systems using Polkit for user authentication management.

  • How do I fix REDHAT-BUG-1655925?

    To fix REDHAT-BUG-1655925, update Polkit to the latest patched version that resolves the user and group ID handling issue.

  • What should I do if I'm affected by REDHAT-BUG-1655925?

    If affected by REDHAT-BUG-1655925, it's essential to apply the relevant security updates and monitor for any unusual authentication behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203