Bug 29944 - polkit new security issue CVE-2021-4034
Summary: polkit new security issue CVE-2021-4034
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK MGA8-32-OK
Keywords: advisory, validated_update
: 29951 29954 (view as bug list)
Depends on:
Blocks:
 
Reported: 2022-01-25 23:11 CET by David Walser
Modified: 2022-01-28 20:55 CET (History)
7 users (show)

See Also:
Source RPM: polkit-0.118-1.1.mga8.src.rpm
CVE:
Status comment:


Attachments

David Walser 2022-01-25 23:11:48 CET

Status comment: (none) => Patch available from upstream
Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Lécureuil 2022-01-26 00:11:43 CET
Fixed in mga8:

src:
    - polkit-0.118-1.1.mga8

CC: (none) => mageia

Comment 2 David Walser 2022-01-26 00:14:11 CET
Advisory:
========================

Updated polkit packages fix security vulnerability:

A local privilege escalation vulnerability was found on polkit's pkexec
utility. The pkexec application is a setuid tool designed to allow unprivileged
users to run commands as privileged users according predefined policies. The
current version of pkexec doesn't handle the calling parameters count correctly
and ends trying to execute environment variables as commands. An attacker can
leverage this by crafting environment variables in such a way it'll induce
pkexec to execute arbitrary code. When successfully executed the attack can
cause a local privilege escalation given unprivileged users administrative
rights on the target machine (CVE-2021-4034).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4034
https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
https://access.redhat.com/errata/RHSA-2022:0267
========================

Updated packages in core/updates_testing:
========================
polkit-0.118-1.1.mga8
libpolkit-gir1.0-0.118-1.1.mga8
libpolkit1_0-0.118-1.1.mga8
libpolkit1-devel-0.118-1.1.mga8

from polkit-0.118-1.1.mga8.src.rpm

Whiteboard: MGA8TOO => (none)
Assignee: bugsquad => qa-bugs
Status comment: Patch available from upstream => (none)
Version: Cauldron => 8

Comment 3 Dave Hodgins 2022-01-26 01:01:23 CET
$ rpm -qa --last |grep ^polkit
polkit-kde-agent-1-5.20.4-1.mga8.x86_64       2021-07-13T18:21:38 EDT
polkit-0.118-1.1.mga8.x86_64                  2021-07-13T18:09:51 EDT

Looks like the release needs to be bumped.

CC: (none) => davidwhodgins

Comment 4 David Walser 2022-01-26 01:04:49 CET
Oh my, you're right.

Updated packages in core/updates_testing:
========================
polkit-0.118-1.2.mga8
libpolkit-gir1.0-0.118-1.2.mga8
libpolkit1_0-0.118-1.2.mga8
libpolkit1-devel-0.118-1.2.mga8

from polkit-0.118-1.2.mga8.src.rpm

Source RPM: polkit-0.120-1.mga9.src.rpm => polkit-0.118-1.1.mga8.src.rpm

Dave Hodgins 2022-01-26 01:07:39 CET

Keywords: (none) => feedback

David Walser 2022-01-26 01:08:52 CET

Keywords: feedback => (none)

Comment 5 Dave Hodgins 2022-01-26 01:13:30 CET
Advisory committed to svn using polkit-0.118-1.2.mga8 for the srpm.

Keywords: (none) => advisory

Comment 6 Dave Hodgins 2022-01-26 01:17:33 CET
Got it from the princeton mirror already. Tested on x86_64 and aarch64.
Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 7 Mageia Robot 2022-01-26 11:31:08 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0037.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 8 Morgan Leijström 2022-01-26 14:02:38 CET
That was really quick!
Well done :)

CC: (none) => fri

Comment 9 Thomas Andrews 2022-01-26 16:15:20 CET
For what it's worth, tried it on a 32-bit Xfce install on 64-bit hardware (Probook 6550b, i3, server kernel), and it worked perfectly. Also on same hardware, 64-bit Plasma install.

Adding the OKs...

Whiteboard: (none) => MGA8-64-OK MGA8-32-OK
CC: (none) => andrewsfarm

Comment 10 David Walser 2022-01-27 16:15:32 CET
*** Bug 29951 has been marked as a duplicate of this bug. ***

CC: (none) => petlaw726

Comment 11 Lewis Smith 2022-01-28 20:55:59 CET
*** Bug 29954 has been marked as a duplicate of this bug. ***

CC: (none) => ubuntu


Note You need to log in before you can comment on or make changes to this bug.