polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync()
Published Feb 16, 2022 ·Due Jun 2, 2023
7.8
HIGHCVSS 3.1
EPSS 23.71%
Description
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected products
- Vendor n/a Product Polkit Defaultn/a
- Version polkit 0.119StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Polkit | n/a |
|
Configuration 1
- < 0.119
Configuration 2
- 11.0
Configuration 3
- 20.04
Configuration 4
- 4.0
- 4.0
Running on/with
- 8.0
Configuration 5
- 4.7
Running on/with
- 7.0
- 8.0
No data.
Red Hat Enterprise Linux 8
polkit-0:0.115-11.el8_4.1
Fixed · RHSA-2021:2238
Red Hat Enterprise Linux 8.1 Extended Update Support
polkit-0:0.115-9.el8_1.1
Fixed · RHSA-2021:2236
Red Hat Enterprise Linux 8.2 Extended Update Support
polkit-0:0.115-11.el8_2.1
Fixed · RHSA-2021:2237
Red Hat OpenShift Container Platform 4.7
cri-o-0:1.20.3-6.rhaos4.7.git0d0f863.el7
Fixed · RHSA-2021:2555
Red Hat OpenShift Container Platform 4.7
dhcp-12:4.3.6-41.el8_3.1
Fixed · RHSA-2021:2555
Red Hat OpenShift Container Platform 4.7
openshift-clients-0:4.7.0-202106252127.p0.git.8b4b094.el7
Fixed · RHSA-2021:2555
Red Hat OpenShift Container Platform 4.7
openshift-kuryr-0:4.7.0-202106232224.p0.git.c7654fb.el8
Fixed · RHSA-2021:2555
Red Hat OpenShift Container Platform 4.7
polkit-0:0.115-11.el8_3.2
Fixed · RHSA-2021:2555
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.4.6-20210615.0.el8_4
Fixed · RHSA-2021:2522
Red Hat Enterprise Linux 6
polkit
Not affected
Red Hat Enterprise Linux 7
polkit
Not affected
Red Hat Enterprise Linux 9
polkit
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | polkit-0:0.115-11.el8_4.1 | Fixed | RHSA-2021:2238 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | polkit-0:0.115-9.el8_1.1 | Fixed | RHSA-2021:2236 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | polkit-0:0.115-11.el8_2.1 | Fixed | RHSA-2021:2237 |
| Red Hat OpenShift Container Platform 4.7 | cri-o-0:1.20.3-6.rhaos4.7.git0d0f863.el7 | Fixed | RHSA-2021:2555 |
| Red Hat OpenShift Container Platform 4.7 | dhcp-12:4.3.6-41.el8_3.1 | Fixed | RHSA-2021:2555 |
| Red Hat OpenShift Container Platform 4.7 | openshift-clients-0:4.7.0-202106252127.p0.git.8b4b094.el7 | Fixed | RHSA-2021:2555 |
| Red Hat OpenShift Container Platform 4.7 | openshift-kuryr-0:4.7.0-202106232224.p0.git.c7654fb.el8 | Fixed | RHSA-2021:2555 |
| Red Hat OpenShift Container Platform 4.7 | polkit-0:0.115-11.el8_3.2 | Fixed | RHSA-2021:2555 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.4.6-20210615.0.el8_4 | Fixed | RHSA-2021:2522 |
| Red Hat Enterprise Linux 6 | polkit | Not affected | n/a |
| Red Hat Enterprise Linux 7 | polkit | Not affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
May 12, 2023
Patch Due
Jun 2, 2023
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jan 29, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (53 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 23.71% (0.23708) | 97.75th | v5 (v2026.06.15) |
| Sep 16, 2026 | 23.71% (0.23708) | 97.70th | v5 (v2026.06.15) |
| Jun 15, 2026 | 22.19% (0.22193) | 97.37th | v5 (v2026.06.15) |
| Jun 11, 2026 | 10.41% (0.10405) | 93.38th | v4 (v2025.03.14) |
| Jun 1, 2026 | 9.10% (0.09100) | 92.80th | v4 (v2025.03.14) |
| May 22, 2026 | 6.41% (0.06409) | 91.15th | v4 (v2025.03.14) |
| May 8, 2026 | 9.55% (0.09551) | 92.90th | v4 (v2025.03.14) |
| Apr 21, 2026 | 7.27% (0.07266) | 91.66th | v4 (v2025.03.14) |
| Mar 29, 2026 | 10.91% (0.10912) | 93.36th | v4 (v2025.03.14) |
| Mar 10, 2026 | 12.39% (0.12390) | 93.76th | v4 (v2025.03.14) |
| Feb 18, 2026 | 10.87% (0.10873) | 93.21th | v4 (v2025.03.14) |
| Feb 10, 2026 | 13.00% (0.12995) | 93.90th | v4 (v2025.03.14) |
| Feb 4, 2026 | 11.42% (0.11416) | 93.39th | v4 (v2025.03.14) |
| Jan 22, 2026 | 8.14% (0.08138) | 91.92th | v4 (v2025.03.14) |
| Jan 7, 2026 | 11.69% (0.11686) | 93.44th | v4 (v2025.03.14) |
| Dec 28, 2025 | 7.75% (0.07754) | 91.64th | v4 (v2025.03.14) |
| Dec 27, 2025 | 4.60% (0.04596) | 88.93th | v4 (v2025.03.14) |
| Dec 18, 2025 | 6.25% (0.06250) | 90.56th | v4 (v2025.03.14) |
| Nov 24, 2025 | 10.10% (0.10096) | 92.80th | v4 (v2025.03.14) |
| Nov 21, 2025 | 6.70% (0.06697) | 90.85th | v4 (v2025.03.14) |
| Nov 18, 2025 | 69.93% (0.69934) | 98.71th | v4 (v2025.03.14) |
| Nov 2, 2025 | 11.52% (0.11522) | 93.36th | v4 (v2025.03.14) |
| Oct 28, 2025 | 14.12% (0.14120) | 94.06th | v4 (v2025.03.14) |
| Oct 27, 2025 | 9.32% (0.09318) | 92.41th | v4 (v2025.03.14) |
| Oct 1, 2025 | 13.22% (0.13217) | 93.92th | v4 (v2025.03.14) |
| Sep 2, 2025 | 8.68% (0.08682) | 92.17th | v4 (v2025.03.14) |
| Aug 30, 2025 | 6.86% (0.06857) | 90.99th | v4 (v2025.03.14) |
| Jul 16, 2025 | 5.35% (0.05351) | 89.61th | v4 (v2025.03.14) |
| Jun 27, 2025 | 8.14% (0.08143) | 91.73th | v4 (v2025.03.14) |
| Jun 15, 2025 | 4.54% (0.04535) | 88.63th | v4 (v2025.03.14) |
| May 25, 2025 | 7.48% (0.07480) | 91.28th | v4 (v2025.03.14) |
| May 15, 2025 | 4.90% (0.04899) | 89.02th | v4 (v2025.03.14) |
| May 14, 2025 | 8.58% (0.08581) | 91.93th | v4 (v2025.03.14) |
| Apr 24, 2025 | 7.54% (0.07540) | 91.31th | v4 (v2025.03.14) |
| Apr 15, 2025 | 4.94% (0.04940) | 89.01th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.56% (0.06560) | 90.22th | v4 (v2025.03.14) |
| Mar 29, 2025 | 12.00% (0.12004) | 89.60th | v4 (v2025.03.14) |
| Mar 28, 2025 | 6.56% (0.06560) | 90.23th | v4 (v2025.03.14) |
| Mar 27, 2025 | 13.41% (0.13409) | 93.20th | v4 (v2025.03.14) |
| Mar 20, 2025 | 7.40% (0.07395) | 90.98th | v4 (v2025.03.14) |
| Mar 19, 2025 | 10.33% (0.10334) | 92.21th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.58% (0.05585) | 89.61th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.18% (0.01177) | 85.67th | v3 (v2023.03.01) |
| Jun 8, 2024 | 1.18% (0.01177) | 85.04th | v3 (v2023.03.01) |
| Jun 12, 2023 | 1.18% (0.01177) | 83.04th | v3 (v2023.03.01) |
| May 13, 2023 | 0.83% (0.00825) | 79.49th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00086) | 34.86th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.50% (0.06503) | 91.06th | v2 (v2022.01.01) |
| Nov 15, 2022 | 6.50% (0.06503) | 90.73th | v2 (v2022.01.01) |
| Jul 15, 2022 | 5.86% (0.05863) | 89.96th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.50% (0.06503) | 90.18th | v2 (v2022.01.01) |
| Mar 1, 2022 | 6.50% (0.06503) | 78.36th | v2 (v2022.01.01) |
| Feb 17, 2022 | 24.07% (0.24072) | 95.21th | v2 (v2022.01.01) |
References (9)
- http://packetstormsecurity.com/files/172836/polkit-Authentication-Bypass.html Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.html Third Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2021-3560 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1961710 Issue TrackingPatchVendor Advisory
- https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/ ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3560
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3560 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2021-3560
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/172836/polkit-Authentication-Bypass.html | Third Party AdvisoryVDB Entry | |
| http://packetstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.html | Third Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2021-3560 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1961710 | Issue TrackingPatchVendor Advisory | |
| https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/ | ExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-3560 | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3560 | government-resourceUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2021-3560 |
Change history (0)
No recorded changes yet.