RHSA-2022:0266: Important: polkit security update
The polkit packages provide a component for controlling system-wide privileges. This component provides a uniform and organized way for non-privileged processes to communicate with privileged ones.Security Fix(es): polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector (CVE-2021-4034) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/polkitto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2 - Upgrade
Upgrade
redhat/polkit-debuginfoto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2 - Upgrade
Upgrade
redhat/polkit-debugsourceto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2 - Upgrade
Upgrade
redhat/polkit-develto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2 - Upgrade
Upgrade
redhat/polkit-docsto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2 - Upgrade
Upgrade
redhat/polkit-libsto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2 - Upgrade
Upgrade
redhat/polkit-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2 - Upgrade
Upgrade
redhat/polkitto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2.aa - Upgrade
Upgrade
redhat/polkit-debuginfoto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2.aa - Upgrade
Upgrade
redhat/polkit-debugsourceto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2.aa - Upgrade
Upgrade
redhat/polkit-develto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2.aa - Upgrade
Upgrade
redhat/polkit-libsto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2.aa - Upgrade
Upgrade
redhat/polkit-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.115-11.el8_4.2.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0266?
RHSA-2022:0266 is classified as a local privilege escalation vulnerability.
How do I fix RHSA-2022:0266?
To fix RHSA-2022:0266, update the polkit packages to version 0.115-11.el8_4.2 or later.
What systems are affected by RHSA-2022:0266?
RHSA-2022:0266 affects various Red Hat Enterprise Linux 8 systems with outdated polkit packages.
Can I continue using my system without addressing RHSA-2022:0266?
Continuing to use your system without addressing RHSA-2022:0266 may expose it to local privilege escalation risks.
What are the impacted packages in RHSA-2022:0266?
The impacted packages in RHSA-2022:0266 include polkit, polkit-debuginfo, polkit-devel, and polkit-libs among others.