Security restrictions bypass in PolicyKit - CVE-2019-6133
Published: January 11, 2019 / Updated: January 14, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to fork() is not atomic, and therefore authorization decisions are improperly cached, related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c. A remote unauthenticated attacker can bypass the "start time" protection mechanism
Affected software
polkit (Alpine package)
linux-azure (Ubuntu package)
linux-oracle (Ubuntu package)
linux-gcp (Ubuntu package)
linux-aws-hwe (Ubuntu package)
polkit (Red Hat package)
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Opensuse
Data Computing Appliance (DCA)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2019-6133
linux-azure (Ubuntu package) - addressed in versions 4.15.0-1040.44, 4.15.0-1040.44~14.04.1
linux-oracle (Ubuntu package) - update to 4.15.0-1009.11~16.04.1
linux-gcp (Ubuntu package) - update to 4.15.0-1028.29~16.04.1
linux-aws-hwe (Ubuntu package) - update to 4.15.0-1033.35~16.04.1
polkit (Red Hat package) - update to 0.96-7.el6_6.1
Data Computing Appliance (DCA) - update to 3.5.3.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009
External References
Related Security Bulletins
- Security restrictions bypass in PolicyKit
- Ubuntu update for Linux kernel (HWE)
- Red Hat update for polkit
- Red Hat update for polkit
- OpenSUSE Linux update for polkit
- Red Hat update for polkit
- Red Hat update for polkit
- Security restrictions bypass in polkit (Alpine package)
- Multiple vulnerabilities in Dell EMC Unity Family, Dell EMC Unity XT Family
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 6.6 Advanced Update Support update for polkit