Back

HIGH KEV

polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync()

Published Feb 16, 2022 ·Due Jun 2, 2023

Description

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected products

Remediation

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 16, 2022
Updated Oct 21, 2025
Reserved May 20, 2021
CISA Vulnrichment
Updated Jan 29, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 3, 2021