polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector
Published Jan 28, 2022 ·Due Jul 18, 2022
7.8
HIGHCVSS 3.1
EPSS 94.34%
Description
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Affected products
- Vendor n/a Product Polkit Defaultn/a
- Version allStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Polkit | n/a |
|
Configuration 1
- < 121
Configuration 2
- 7.6
- 7.7
- 8.0
- 7.0
- 8.2
- 7.0
- 8.0
- 8.2
- 8.4
- 7.0
- 7.0
- 8.0
- 8.1
- 8.2
- 8.4
- 7.0
- 6.0
- 7.0
- 7.3
- 7.4
- 7.6
- 7.7
- 8.2
- 8.4
- 8.4
- 7.6
- 7.7
- 8.2
- 8.4
- 8.1
- 8.2
- 8.4
- 7.0
Configuration 3
- 14.04
- 16.04
- 18.04
- 20.04
- 21.10
Configuration 4
- 7.0
- 15.0
- 4.1
- 4.1
- 15
- 15
- 15
- 12
Configuration 5
- 12.2.1.3.0
- 12.2.1.4.0
- 8.8
Configuration 6
- < 3.3.0
Configuration 7
- < 2.0
Running on/with
- n/a
Configuration 8
- 1.0
- v8
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support
polkit-0:0.96-11.el6_10.2
Fixed · RHSA-2022:0269
Red Hat Enterprise Linux 7
polkit-0:0.112-26.el7_9.1
Fixed · RHSA-2022:0274
Red Hat Enterprise Linux 7.3 Advanced Update Support
polkit-0:0.112-12.el7_3.1
Fixed · RHSA-2022:0270
Red Hat Enterprise Linux 7.4 Advanced Update Support
polkit-0:0.112-12.el7_4.2
Fixed · RHSA-2022:0272
Red Hat Enterprise Linux 7.6 Advanced Update Support
polkit-0:0.112-18.el7_6.3
Fixed · RHSA-2022:0271
Red Hat Enterprise Linux 7.6 Telco Extended Update Support
polkit-0:0.112-18.el7_6.3
Fixed · RHSA-2022:0271
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
polkit-0:0.112-18.el7_6.3
Fixed · RHSA-2022:0271
Red Hat Enterprise Linux 7.7 Advanced Update Support
polkit-0:0.112-22.el7_7.2
Fixed · RHSA-2022:0273
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
polkit-0:0.112-22.el7_7.2
Fixed · RHSA-2022:0273
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
polkit-0:0.112-22.el7_7.2
Fixed · RHSA-2022:0273
Red Hat Enterprise Linux 8
polkit-0:0.115-13.el8_5.1
Fixed · RHSA-2022:0267
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
polkit-0:0.115-9.el8_1.2
Fixed · RHSA-2022:0268
Red Hat Enterprise Linux 8.2 Extended Update Support
polkit-0:0.115-11.el8_2.2
Fixed · RHSA-2022:0265
Red Hat Enterprise Linux 8.4 Extended Update Support
polkit-0:0.115-11.el8_4.2
Fixed · RHSA-2022:0266
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.21-20220126.0.el7_9
Fixed · RHSA-2022:0443
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.4.10-202202081536_8.5
Fixed · RHSA-2022:0540
Red Hat Enterprise Linux 9
polkit
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | polkit-0:0.96-11.el6_10.2 | Fixed | RHSA-2022:0269 |
| Red Hat Enterprise Linux 7 | polkit-0:0.112-26.el7_9.1 | Fixed | RHSA-2022:0274 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | polkit-0:0.112-12.el7_3.1 | Fixed | RHSA-2022:0270 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | polkit-0:0.112-12.el7_4.2 | Fixed | RHSA-2022:0272 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | polkit-0:0.112-18.el7_6.3 | Fixed | RHSA-2022:0271 |
| Red Hat Enterprise Linux 7.6 Telco Extended Update Support | polkit-0:0.112-18.el7_6.3 | Fixed | RHSA-2022:0271 |
| Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions | polkit-0:0.112-18.el7_6.3 | Fixed | RHSA-2022:0271 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | polkit-0:0.112-22.el7_7.2 | Fixed | RHSA-2022:0273 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | polkit-0:0.112-22.el7_7.2 | Fixed | RHSA-2022:0273 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | polkit-0:0.112-22.el7_7.2 | Fixed | RHSA-2022:0273 |
| Red Hat Enterprise Linux 8 | polkit-0:0.115-13.el8_5.1 | Fixed | RHSA-2022:0267 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | polkit-0:0.115-9.el8_1.2 | Fixed | RHSA-2022:0268 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | polkit-0:0.115-11.el8_2.2 | Fixed | RHSA-2022:0265 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | polkit-0:0.115-11.el8_4.2 | Fixed | RHSA-2022:0266 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.21-20220126.0.el7_9 | Fixed | RHSA-2022:0443 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.4.10-202202081536_8.5 | Fixed | RHSA-2022:0540 |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
For customers who cannot update immediately and doesn't have Secure Boot feature enabled, the issue can be mitigated by executing the following steps: 1) Install required systemtap packages and dependencies as per - pointed by https://access.redhat.com/solutions/5441 2) Install polkit debug info: ~~~ debuginfo-install polkit ~~~ 3) Create the following systemtap script, and name it pkexec-block.stp: ~~~ probe process("/usr/bin/pkexec").function("main") { if (cmdline_arg(1) == "") raise(9); } ~~~ 4) Load the systemtap module into the running kernel: ~~~ stap -g -F -m stap_pkexec_block pkexec_block.stp ~~~ 5) Ensure the module is loaded: ~~~ lsmod | grep -i stap_pkexec_block stap_pkexec_block 434176 0 ~~~ 6) Once polkit package was updated to the version containing the fix, the systemtap generated kernel module can be removed by running: ~~~ rmmod stap_pkexec_block ~~~ This mitigation doesn't work for Secure Boot enabled system as SystemTap would require an external compiling server to be able to sign the generated kernel module with a key enrolled into the Kernel's keyring.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
Jun 27, 2022
Patch Due
Jul 18, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 12, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (46 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 94.34% (0.94345) | 99.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 94.92% (0.94921) | 99.85th | v5 (v2026.06.15) |
| Mar 16, 2026 | 87.81% (0.87811) | 99.46th | v4 (v2025.03.14) |
| Mar 1, 2026 | 86.73% (0.86734) | 99.42th | v4 (v2025.03.14) |
| Feb 18, 2026 | 87.85% (0.87848) | 99.46th | v4 (v2025.03.14) |
| Feb 1, 2026 | 86.73% (0.86734) | 99.42th | v4 (v2025.03.14) |
| Jan 27, 2026 | 87.85% (0.87848) | 99.45th | v4 (v2025.03.14) |
| Jan 23, 2026 | 89.04% (0.89041) | 99.51th | v4 (v2025.03.14) |
| Jan 18, 2026 | 87.07% (0.87073) | 99.42th | v4 (v2025.03.14) |
| Jan 15, 2026 | 88.44% (0.88442) | 99.48th | v4 (v2025.03.14) |
| Jan 8, 2026 | 87.12% (0.87119) | 99.42th | v4 (v2025.03.14) |
| Jan 5, 2026 | 88.56% (0.88558) | 99.48th | v4 (v2025.03.14) |
| Dec 13, 2025 | 87.12% (0.87119) | 99.41th | v4 (v2025.03.14) |
| Dec 1, 2025 | 83.38% (0.83383) | 99.24th | v4 (v2025.03.14) |
| Nov 21, 2025 | 84.97% (0.84966) | 99.30th | v4 (v2025.03.14) |
| Nov 18, 2025 | 92.97% (0.92970) | 99.84th | v4 (v2025.03.14) |
| Oct 31, 2025 | 83.93% (0.83929) | 99.25th | v4 (v2025.03.14) |
| Oct 30, 2025 | 87.03% (0.87035) | 99.40th | v4 (v2025.03.14) |
| Oct 29, 2025 | 83.93% (0.83929) | 99.25th | v4 (v2025.03.14) |
| Oct 17, 2025 | 87.77% (0.87772) | 99.43th | v4 (v2025.03.14) |
| Oct 2, 2025 | 86.11% (0.86106) | 99.37th | v4 (v2025.03.14) |
| Sep 20, 2025 | 87.26% (0.87257) | 99.41th | v4 (v2025.03.14) |
| Sep 16, 2025 | 88.54% (0.88540) | 99.48th | v4 (v2025.03.14) |
| Sep 10, 2025 | 86.96% (0.86964) | 99.40th | v4 (v2025.03.14) |
| Aug 27, 2025 | 85.74% (0.85737) | 99.33th | v4 (v2025.03.14) |
| Aug 1, 2025 | 86.84% (0.86840) | 99.41th | v4 (v2025.03.14) |
| Jun 15, 2025 | 88.29% (0.88286) | 99.45th | v4 (v2025.03.14) |
| Jun 5, 2025 | 89.67% (0.89671) | 99.53th | v4 (v2025.03.14) |
| Jun 4, 2025 | 88.62% (0.88616) | 99.47th | v4 (v2025.03.14) |
| May 24, 2025 | 89.76% (0.89763) | 99.53th | v4 (v2025.03.14) |
| Mar 17, 2025 | 87.76% (0.87759) | 99.44th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.14% (0.00145) | 51.88th | v3 (v2023.03.01) |
| Jun 29, 2024 | 0.12% (0.00122) | 46.92th | v3 (v2023.03.01) |
| May 7, 2024 | 0.05% (0.00046) | 16.08th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 14.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.11% (0.04106) | 86.02th | v2 (v2022.01.01) |
| Feb 14, 2023 | 4.11% (0.04106) | 85.64th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.37% (0.02365) | 80.88th | v2 (v2022.01.01) |
| Nov 15, 2022 | 4.11% (0.04106) | 85.57th | v2 (v2022.01.01) |
| Oct 6, 2022 | 9.68% (0.09677) | 94.06th | v2 (v2022.01.01) |
| Jul 15, 2022 | 13.06% (0.13064) | 95.41th | v2 (v2022.01.01) |
| Apr 1, 2022 | 8.95% (0.08954) | 93.48th | v2 (v2022.01.01) |
| Mar 4, 2022 | 8.95% (0.08954) | 83.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.64% (0.03644) | 66.63th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.23% (0.04225) | 74.12th | v1 |
| Jan 29, 2022 | 4.23% (0.04225) | 74.09th | v1 |
References (17)
- http://packetstormsecurity.com/files/166196/Polkit-pkexec-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/166200/Polkit-pkexec-Privilege-Escalation.html Third Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2021-4034 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2022-001 MitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2025869 Issue TrackingPatch
- https://cert-portal.siemens.com/productcert/pdf/ssa-330556.pdf Third Party Advisory
- https://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683 Patch
- https://nvd.nist.gov/vuln/detail/CVE-2021-4034
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-4034 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2021-4034
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt ExploitMitigationThird Party Advisory
- https://www.secpod.com/blog/local-privilege-escalation-vulnerability-in-major-linux-distributions-cve-2021-4034/ ExploitThird Party Advisory
- https://www.starwindsoftware.com/security/sw-20220818-0001/ Third Party Advisory
- https://www.suse.com/support/kb/doc/?id=000020564 Third Party Advisory
- https://www.vicarius.io/vsociety/posts/pwnkit-pkexec-lpe-cve-2021-4034 ExploitThird Party Advisory
Change history (0)
No recorded changes yet.