Input validation error in polkit - CVE-2021-4034
Published: January 26, 2022 / Updated: April 27, 2023
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper handling of the calling parameters count in the pkexec setuid binary, which causes the binary to execute environment variables as commands. A local user can craft environment variables in a way that they will be processed and executed by pkexec and execute arbitrary commands on the system as root.
Affected software
EMC Cloud Tiering Appliance
Isilon InsightIQ
Dell Hybrid Client
Aruba Analytics and Location Engine
Aruba Central On-Premises
Disk Library for mainframe (DLm)
XtremIO X2
ClearPass Policy Manager
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
VASA Provider Standalone
Amazon Linux AMI
Arch Linux
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE MicroOS
Alletra OS
Red Hat Enterprise Linux Server - Extended Life Cycle Support
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
IBM Netezza PDA OS Security
Bubblewrap
IBM Cloud Pak for Data System
Oracle SD-WAN Edge
Red Hat Advanced Cluster Management for Kubernetes
Session Smart Router
Connectrix MDS-DCNM
policykit-1 (Debian package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libmetalink (Red Hat package)
polkit (Red Hat package)
policykit-1 (Ubuntu package)
polkit
polkit-devel
polkit-docs
polkit-debuginfo
polkit-debugsource
typelib-1_0-Polkit-1_0
libpolkit0-32bit
libpolkit0-debuginfo-32bit
polkit-devel-debuginfo
libpolkit0-debuginfo
libpolkit0
polkit-libs
polkit-help
wget (Red Hat package)
Lumada APM Edge
SINUMERIK Edge
IBM Cloud Pak System
Red Hat Virtualization
Solutions Enabler Virtual Appliance
Red Hat Virtualization Host
Contrail Networking
Red Hat OpenShift Container Platform
Nimble Storage
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
IBM Qradar SIEM
IBM Security Guardium
SCALANCE LPE9403
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M876-4 (NAM)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (EU)
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
RecoverPoint for VMs
SCALANCE S615
How to mitigate CVE-2021-4034
Bubblewrap - update to 0.6.0
policykit-1 (Debian package) - addressed in versions 0.105-25+deb10u1, 0.105-31+deb11u1
Lumada APM Edge - update to 6.3
IBM Cloud Pak System - update to 2.3.3.5
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.21-1.el7ev, 4.4.10-1.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.3.21-20220126.0.el7_9
Red Hat OpenShift Container Platform - update to 4.7.43
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10 Interim Fix 02, 7.4.3 Fix Pack 4 Interim Fix 04, 7.5.0 Update Pack 1
libmetalink (Red Hat package) - update to 0.1.3-7.el8
polkit (Red Hat package) - addressed in versions 0.96-11.el6_10.2, 0.112-12.el7_3.1, 0.112-12.el7_4.2, 0.112-18.el7_6.3, 0.112-22.el7_7.2, 0.112-26.el7_9.1, 0.115-9.el8_1.2, 0.115-11.el8_2.2, 0.115-11.el8_4.2, 0.115-13.el8_5.1
policykit-1 (Ubuntu package) - addressed in versions 0.105-20ubuntu0.18.04.6, 0.105-26ubuntu1.2, 0.105-31ubuntu0.1, 0.10514.1ubuntu0.5+esm1
polkit - addressed in versions 0.112-26, 0.115-13
polkit-devel - addressed in versions 0.112-26, 0.115-13
polkit-docs - addressed in versions 0.112-26, 0.115-13
polkit - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
polkit-debuginfo - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
polkit-debugsource - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
typelib-1_0-Polkit-1_0 - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
libpolkit0-32bit - update to 0.113-5.24.1
libpolkit0-debuginfo-32bit - update to 0.113-5.24.1
polkit-devel - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
polkit-devel-debuginfo - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
libpolkit0-debuginfo - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
libpolkit0 - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
polkit-libs - update to 0.115-13
polkit-help - update to 0.116-8
polkit-debuginfo - update to 0.116-8
polkit-devel - update to 0.116-8
polkit-libs - update to 0.116-8
polkit-debugsource - update to 0.116-8
polkit - update to 0.116-8
polkit - addressed in versions 0.117-3.fc34.2, 0.120-1.fc35.1
polkit - update to 0.117-10
wget (Red Hat package) - update to 1.19.5-10.el8
SCALANCE LPE9403 - update to 2.0
Aruba Analytics and Location Engine - update to 2.2.0.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.6
Aruba Central On-Premises - update to 2.5.4.3
SINUMERIK Edge - update to 3.3.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
RecoverPoint for VMs - update to 5.3.3
Session Smart Router - addressed in versions 5.4.7, 5.5.3
Disk Library for mainframe (DLm) - update to 5.5.0.0
XtremIO X2 - update to 6.4.2-13
ClearPass Policy Manager - addressed in versions 6.8.9 Hotfix 2, 6.9.10, 6.10.4
SCALANCE M804PB - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE S615 EEC - update to 7.2
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.19, 9.2.3.1
Solutions Enabler - addressed in versions 9.1.0.19, 9.2.3.1
Unisphere 360 - addressed in versions 9.1.0.30, 9.2.3.4
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.32, 9.2.3.11
Unisphere for PowerMax - addressed in versions 9.1.0.32, 9.2.3.11
VASA Provider Standalone - addressed in versions 9.1.0.724, 9.2.3.10
Connectrix MDS-DCNM - update to 11.5(4)
Contrail Networking - update to 2011.L5
Links to Public Exploits and PoC-codes
- Exploit #9012 - CVE-Exploits (CVE-Exploits) (April 27, 2023)
- Exploit #8849 - CVE-2021-4034 () (February 20, 2023)
- Exploit #8840 - CVE-2021-4034 (PoC CVE 2021-4034 PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec) (February 15, 2023)
- Exploit #8652 - CVE-2021-4034- (PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)) (December 7, 2022)
- Exploit #8475 - poppy (CVE-2021-4034 PoC , polkit < 0.131) (October 16, 2022)
- Exploit #8457 - AutoPwnkit (A tool to automate the exploit PWNKIT (CVE-2021-4034)) (October 10, 2022)
- Exploit #8410 - CVE-2021-4034 (Vulnerability to CVE-2021-4034 Pwnkit) (September 27, 2022)
- Exploit #8330 - CVE-2021-4034 (pwnkit auto exploiter written in Go, no network connectivity required.) (September 3, 2022)
- Exploit #8260 - CVE-2021-4034-exploit (I am not the real author of this exploits.. There are two exploits available, use any of one if it doesn't work use another one... Manual for this two exploit has given in README file. Please read that file before using it.. :) ) (August 16, 2022)
- Exploit #8245 - Kernel-Exploits (Kernel exploits consisting mostly of privilege escalation attacks against core components of Linux distribtions) (August 14, 2022)
- Exploit #8108 - cve-2021-4034 (port of CVE-2021-4034 exploit to Rust/cargo for my own edification) (July 4, 2022)
- Exploit #8107 - pkexec-exploit (pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)) (July 4, 2022)
- Exploit #8064 - Pwnkit-go (A golang based exp for CVE-2021-4034 dubbed pwnkit (more features added......)) (June 22, 2022)
- Exploit #7998 - CVE-2021-4034 (Exploit modificado para el tito Eu) (June 9, 2022)
- Exploit #7932 - cve-2021-4034 (CVE-2021-4034 for single commcand) (May 31, 2022)
- Exploit #7821 - PolicyKit-1 0.105-31 - Privilege Escalation (May 13, 2022)
- Exploit #7783 - Local Privilege Escalation in polkits pkexec (May 12, 2022)
- Exploit #7677 - CVE-2021-4034 (PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python) (April 21, 2022)
- Exploit #7514 - CVE-2021-4034 () (March 17, 2022)
- Exploit #7495 - PWNKITVulnerability (CVE-2021-4034 (PWNKIT).) (March 15, 2022)
- Exploit #7493 - pwnkit-vulnerability (CVE-2021-4034 (PWNKIT).) (March 15, 2022)
- Exploit #7403 - ez-pwnkit (Go implementation of the PwnKit Linux Local Privilege Escalation exploit (CVE-2021-4034)) (March 2, 2022)
- Exploit #7366 - CVE-2021-4034 (PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python) (February 21, 2022)
- Exploit #7363 - CVE-2021-4034 (pkexec EoP exploit) (February 20, 2022)
- Exploit #7359 - CVE-2021-4034 (A simple PWNKIT file to convert you to root ) (February 16, 2022)
- Exploit #7358 - CVE-2021-4034 (CVE-2021-4034 centos8可用版本) (February 16, 2022)
- Exploit #7345 - CVE-2022-4034 (A simple PWNKIT file to convert you to root ) (February 13, 2022)
- Exploit #7343 - pwncat_pwnkit (pwncat module that automatically exploits CVE-2021-4034 (pwnkit)) (February 13, 2022)
- Exploit #7342 - lsm_bpf_check_argc0 (LSM BPF module to block pwnkit (CVE-2021-4034) like exploits) (February 13, 2022)
- Exploit #7336 - polkit_CVE-2021-4034 (Ansible role to patch RHSB-2022-001 Polkit Privilege Escalation - (CVE-2021-4034)) (February 9, 2022)
- Exploit #7333 - CVE-2021-4034-NoGCC (CVE-2021-4034简单优化,以应对没有安装gcc和make的目标环境) (February 9, 2022)
- Exploit #7332 - CVE-2021-4034 (Proof of Concept for CVE-2021-4034 Polkit Privilege Escalation) (February 9, 2022)
- Exploit #7331 - pwnkit (CVE-2021-4034 PoC) (February 8, 2022)
- Exploit #7327 - CVE-2021-4034 (Pwnkit Exploit (CVE-2021-4034), no download capabilty? Copy and paste it!) (February 8, 2022)
- Exploit #7326 - polkit-0.96-CVE-2021-4034 (centos 6.10 rpm for fix polkit CVE-2021-4034; centos 6.10的rpm包,修复CVE-2021-4034 漏洞) (February 8, 2022)
- Exploit #7323 - CVE-2021-4034 (An exploit for CVE-2021-4034 aka Pwnkit: Local Privilege Escalation in polkit's pkexec) (February 6, 2022)
- Exploit #7321 - CVE-2021-4034 (pkexec (Polkit) exploit of Privilege Escalation vulnerability CVE-2021-4034) (February 6, 2022)
- Exploit #7318 - PwnKit-Hunter (PwnKit-Hunter is here to help you check if your systems are vulnerable to CVE-2021-4043, a.k.a. PwnKit) (February 4, 2022)
- Exploit #7314 - PoC-CVE-2021-4034 (Pwnkit CVE-2021-4034) (February 1, 2022)
- Exploit #7310 - CVE-2021-4034 (Pre-compiled builds for CVE-2021-4034) (January 31, 2022)
- Exploit #7307 - Polkit-pkexec-exploit-for-Linux (CVE-2021-4034) (January 31, 2022)
- Exploit #7306 - pwnkit-go (Exploit for the PwnKit vulnerability, CVE-2021-4034, written in Go) (January 30, 2022)
- Exploit #7305 - cve-2021-4034 (PoC for cve-2021-4034) (January 30, 2022)
- Exploit #7303 - CVE-2021-4034-PwnKit (PwnKit PoC for Polkit pkexec CVE-2021-4034 ) (January 30, 2022)
- Exploit #7302 - CVE-2021-4034 (CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation) (January 30, 2022)
- Exploit #7301 - POC-CVE-2021-4034 () (January 30, 2022)
- Exploit #7297 - CVE-2021-4034 (CVE-2021-4034) (January 30, 2022)
- Exploit #7293 - CVE-2020-4034 (Polkit pkexec CVE-2021-4034 Proof Of Concept and Patching) (January 27, 2022)
- Exploit #7291 - CVE-2021-4034 () (January 27, 2022)
- Exploit #7290 - CVE-2021-4034-POC () (January 27, 2022)
- Exploit #7289 - PwnKit-Exploit (Proof of Concept (PoC) CVE-2021-4034 ) (January 27, 2022)
- Exploit #7288 - CVE-2021-4034 (PoC for CVE-2021-4034) (January 27, 2022)
- Exploit #7287 - pwnkit (PoC for the CVE-2021-4034 vulnerability, affecting polkit < 0.120.) (January 27, 2022)
- Exploit #7286 - -CVE-2021-4034 () (January 27, 2022)
- Exploit #7281 - CVE-2021-4034 (Exploit for CVE-2021-4034) (January 27, 2022)
- Exploit #7280 - pkwner (A python3 and bash PoC for CVE-2021-4034 by Kim Schulz) (January 27, 2022)
- Exploit #7278 - CVE-2021-4034 () (January 27, 2022)
- Exploit #7277 - CVE-2021-4034 (Pseudopatch for CVE-2021-4034) (January 27, 2022)
- Exploit #7276 - CVE-2021-4034 (Linux system service bug gives root on all major distros, exploit published A vulnerability in the pkexec component of Polkit identified as CVE-2021-4034 PwnKit is present in the default configuration of all major Linux distributions and ca (January 27, 2022)
- Exploit #7275 - CVE-2021-4034 (CVE-2021-4034: Local Privilege Escalation in polkit's pkexec proof of concept) (January 27, 2022)
- Exploit #7274 - CVE-2021-4034 (CVE-2021-4034 POC and Docker and Analysis write up) (January 27, 2022)
- Exploit #7273 - pwnkit-exploit (CVE-2021-4034 POC exploit) (January 27, 2022)
- Exploit #7272 - pkexec-lpe-poc (POC for CVE-2021-4034) (January 27, 2022)
- Exploit #7271 - cve-2021-4034 (PoC for cve-2021-4034) (January 27, 2022)
- Exploit #7270 - CVE-2021-4034 (polkit pkexec Local Privilege Vulnerability to Add custom commands) (January 27, 2022)
- Exploit #7269 - CVE-2021-4034 (CVE-2021-4034) (January 27, 2022)
- Exploit #7268 - CVE-2021-4034 (Local Privilege Escalation in polkit's pkexec) (January 27, 2022)
- Exploit #7267 - CVE-2021-4034 (Python exploit code for CVE-2021-4034 (pwnkit)) (January 27, 2022)
- Exploit #7266 - poc-cve-2021-4034 (PoC for CVE-2021-4034 dubbed pwnkit) (January 27, 2022)
- Exploit #7265 - PwnKit (Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation) (January 27, 2022)
- Exploit #7264 - CVE-2021-4034 (A Golang implementation of clubby789's implementation of CVE-2021-4034) (January 27, 2022)
- Exploit #7263 - CVE-2021-4034 (PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)) (January 27, 2022)
- Exploit #7262 - CVE-2021-4034 (CVE-2021-4034 1day) (January 27, 2022)
External References
Related Security Bulletins
- Privilege escalation in polkit pkexec
- Red Hat Enterprise Linux 8.2 update for polkit
- Red Hat Enterprise Linux 8.4 update for polkit
- Red Hat Enterprise Linux 8 update for polkit
- Red Hat Enterprise Linux 8.1 update for polkit
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for polkit
- Red Hat Enterprise Linux 7.3 update for polkit
- Red Hat Enterprise Linux 7.6 update for polkit
- Red Hat Enterprise Linux 7.4 update for polkit
- Red Hat Enterprise Linux 7.7 update for polkit
- Red Hat Enterprise Linux 7 update for polkit
- Debian update for policykit-1
- Slackware Linux update for polkit
- CentOS 7 update for polkit
- Gentoo update for Polkit
- Privilege escalation in IBM Netezza PDA OS Security
- Multiple vulnerabilities in Red Hat Virtualization
- Multiple vulnerabilities in Red Hat Virtualization
- Multiple vulnerabilities in OpenShift Container Platform 4.7
- Privilege escalation in IBM Cloud Pak for Data System 1.0
- Privilege escalation in QRadar SIEM
- Privilege escalation in Bubblewrap
- Arch Linux update for polkit
- IBM Security Guardium update for PolicyKit
- Privilege escalation in Siemens SCALANCE LPE9403 and SINUMERIK Edge Products
- Ubuntu update for policykit-1
- Ubuntu update for policykit-1
- Privilege escalation in IBM Cloud Pak System
- Privilege escalation in Dell Disk Library for mainframe
- Multiple vulnerabilities in Dell EMCRecoverPoint
- Privilege escalation in Dell Connectrix
- Multiple Linux kernel vulnerabilities in Hitachi Energy Lumada APM Edge
- Privilege escalation in Dell EMC Cloud Tiering Appliance
- Multiple vulnerabilities in Juniper Networks Contrail Networking
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in Oracle SD-WAN Edge
- Privilege escalation in Dell Hybrid Client
- Privilege escalation in Dell InsightIQ
- Multiple vulnerabilities in Dell Unisphere for PowerMax, Dell Solutions Enabler, Dell Unisphere 360 and Dell VASA Provider
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- SUSE update for polkit
- SUSE update for polkit
- SUSE update for polkit
- Input validation error in HPE Nimble Storage and HPE Alletra 6000
- Input validation error in HPE Aruba Analytics and Location Engine, Aruba Central On Prem (COP), and Aruba ClearPass Policy Manager
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- openEuler update for polkit
- Amazon Linux AMI update for polkit
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.3
- Fedora 35 update for polkit
- Fedora 34 update for polkit
- Multiple vulnerabilities in Dell XtremIO X2
- Anolis OS update for polkit
- Anolis OS update for polkit