Database/Kernel, userspace & hypervisor
polkit (pkexec): PwnKit: local privilege escalation to root via argv handling
CVSS 7.8CVE-2021-4034Kernel, userspace & hypervisorKnown exploitedcurated
Impact
PwnKit: local privilege escalation to root via argv handling; no exploit prerequisites [KEV]
Who can reach it
Local user, incl. any shell inside a privileged/host-namespace container
What to do
Package update only; no reboot. Interim mitigation: chmod 0755 /usr/bin/pkexec (strip setuid)
References
Related entries
- Linux kernel (net/smc): The CDC send-completion handler takes a lock inside an smc_sock that close() has already freedCVE-2021-46925 · Linux kernel (net/smc)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amd/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2021-47551 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amd/amdkfd)High
- Linux kernel (arch/x86/kvm/mmu): The TDP MMU skipped invalid roots when unmapping a GFN range, so KVM could still holdCVE-2021-47639 · Linux kernel (arch/x86/kvm/mmu)High
- Linux kernel (fs_context): Heap overflow in legacy filesystem parameter handlingCVE-2022-0185 · Linux kernel (fs_context)High
- Linux i915 GPU kernel driver (GTT TLB handling): Stale GPU TLB entries let the GPU keep reading physical pages afterCVE-2022-0330 · Linux i915 GPU kernel driver (GTT TLB handling)High
- Linux kernel (pipe): Dirty Pipe: uninitialised pipe_buffer flags allow overwriting read-only files, inclCVE-2022-0847 · Linux kernel (pipe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.