Vulnerability Description
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Polkit Project | Polkit | 0.117 |
| Redhat | Enterprise Linux | 8.0 |
| Fedoraproject | Fedora | 34 |
| Canonical | Ubuntu Linux | 20.04 |
| Debian | Debian Linux | 11.0 |
| Oracle | Zfs Storage Appliance Kit | 8.8 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/172849/polkit-File-Descriptor-Exhaustion.ht
- https://access.redhat.com/security/cve/cve-2021-4115Third Party Advisory
- https://gitlab.com/redhat/centos-stream/rpms/polkit/-/merge_requests/6/diffs?comPatchThird Party Advisory
- https://gitlab.freedesktop.org/polkit/polkit/-/issues/141ExploitIssue TrackingPatch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
- http://packetstormsecurity.com/files/172849/polkit-File-Descriptor-Exhaustion.ht
- https://access.redhat.com/security/cve/cve-2021-4115Third Party Advisory
- https://gitlab.com/redhat/centos-stream/rpms/polkit/-/merge_requests/6/diffs?comPatchThird Party Advisory
- https://gitlab.freedesktop.org/polkit/polkit/-/issues/141ExploitIssue TrackingPatch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatchThird Party Advisory
FAQ
What is CVE-2021-4115?
CVE-2021-4115 is a vulnerability with a CVSS score of 5.5 (MEDIUM). There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE:...
How severe is CVE-2021-4115?
CVE-2021-4115 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-4115?
Check the references section above for vendor advisories and patch information. Affected products include: Polkit Project Polkit, Redhat Enterprise Linux, Fedoraproject Fedora, Canonical Ubuntu Linux, Debian Debian Linux.