#VU60007 Input validation error in polkit - CVE-2021-4034
Published: January 26, 2022 / Updated: April 27, 2023
polkit
Freedesktop.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper handling of the calling parameters count in the pkexec setuid binary, which causes the binary to execute environment variables as commands. A local user can craft environment variables in a way that they will be processed and executed by pkexec and execute arbitrary commands on the system as root.