First published: Tue Nov 23 2021(Updated: )
A Local Privilege Escalation vulnerability (from any user to root) was found in polkit's pkexec, a SUID-root program that is installed by default on every major Linux distribution.
Affected Software | Affected Version | How to fix |
---|---|---|
polkit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2025869 is considered high due to its potential for local privilege escalation from any user to root.
To fix REDHAT-BUG-2025869, update the polkit package to the latest version provided by your Linux distribution's repositories.
All major Linux distributions that include the polkit's pkexec application are affected by REDHAT-BUG-2025869.
REDHAT-BUG-2025869 is a Local Privilege Escalation vulnerability affecting the pkexec component of polkit.
Polkit's pkexec is a SUID-root program that allows users to execute commands as another user, and it is the component exploited in REDHAT-BUG-2025869.