GPU VulnDB

Database/Kernel, userspace & hypervisor

polkit (pkexec): PwnKit: local privilege escalation to root via argv handling

CVE-2021-4034Kernel, userspace & hypervisorKnown exploitedcurated

Impact

PwnKit: local privilege escalation to root via argv handling; no exploit prerequisites [KEV]

Who can reach it

Local user, incl. any shell inside a privileged/host-namespace container

What to do

Package update only; no reboot. Interim mitigation: chmod 0755 /usr/bin/pkexec (strip setuid)

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.