Input validation error in polkit - CVE-2021-4034

 

Input validation error in polkit - CVE-2021-4034

Published: January 26, 2022 / Updated: April 27, 2023


Vulnerability identifier: #VU60007
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-4034
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper handling of the calling parameters count in the pkexec setuid binary, which causes the binary to execute environment variables as commands. A local user can craft environment variables in a way that they will be processed and executed by pkexec and execute arbitrary commands on the system as root.


Affected software

polkit
EMC Cloud Tiering Appliance
Isilon InsightIQ
Dell Hybrid Client
Aruba Analytics and Location Engine
Aruba Central On-Premises
Disk Library for mainframe (DLm)
XtremIO X2
ClearPass Policy Manager
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
VASA Provider Standalone
Amazon Linux AMI
Arch Linux
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE MicroOS
Alletra OS
Red Hat Enterprise Linux Server - Extended Life Cycle Support
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Anolis OS
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
IBM Netezza PDA OS Security
Bubblewrap
IBM Cloud Pak for Data System
Oracle SD-WAN Edge
Red Hat Advanced Cluster Management for Kubernetes
Session Smart Router
Connectrix MDS-DCNM
policykit-1 (Debian package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libmetalink (Red Hat package)
polkit (Red Hat package)
policykit-1 (Ubuntu package)
polkit
polkit-devel
polkit-docs
polkit-debuginfo
polkit-debugsource
typelib-1_0-Polkit-1_0
libpolkit0-32bit
libpolkit0-debuginfo-32bit
polkit-devel-debuginfo
libpolkit0-debuginfo
libpolkit0
polkit-libs
polkit-help
wget (Red Hat package)
Lumada APM Edge
SINUMERIK Edge
IBM Cloud Pak System
Red Hat Virtualization
Solutions Enabler Virtual Appliance
Red Hat Virtualization Host
Contrail Networking
Red Hat OpenShift Container Platform
Nimble Storage
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
IBM Qradar SIEM
IBM Security Guardium
SCALANCE LPE9403
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M876-4 (NAM)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M826-2 SHDSL-Router
SCALANCE M874-2
SCALANCE M874-3
SCALANCE M876-3 (EVDO)
SCALANCE M876-3 (ROK)
SCALANCE M876-4
SCALANCE M876-4 (EU)
RUGGEDCOM RM1224 LTE(4G) EU
SCALANCE MUM853-1 (EU)
SCALANCE MUM856-1 (EU)
SCALANCE MUM856-1 (RoW)
SCALANCE S615 EEC
RecoverPoint for VMs
SCALANCE S615

How to mitigate CVE-2021-4034

Install update from vendor's website.

polkit - update to 121
Bubblewrap - update to 0.6.0
policykit-1 (Debian package) - addressed in versions 0.105-25+deb10u1, 0.105-31+deb11u1
Lumada APM Edge - update to 6.3
IBM Cloud Pak System - update to 2.3.3.5
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.21-1.el7ev, 4.4.10-1.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.3.21-20220126.0.el7_9
Red Hat OpenShift Container Platform - update to 4.7.43
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10 Interim Fix 02, 7.4.3 Fix Pack 4 Interim Fix 04, 7.5.0 Update Pack 1
libmetalink (Red Hat package) - update to 0.1.3-7.el8
polkit (Red Hat package) - addressed in versions 0.96-11.el6_10.2, 0.112-12.el7_3.1, 0.112-12.el7_4.2, 0.112-18.el7_6.3, 0.112-22.el7_7.2, 0.112-26.el7_9.1, 0.115-9.el8_1.2, 0.115-11.el8_2.2, 0.115-11.el8_4.2, 0.115-13.el8_5.1
policykit-1 (Ubuntu package) - addressed in versions 0.105-20ubuntu0.18.04.6, 0.105-26ubuntu1.2, 0.105-31ubuntu0.1, 0.10514.1ubuntu0.5+esm1
polkit - addressed in versions 0.112-26, 0.115-13
polkit-devel - addressed in versions 0.112-26, 0.115-13
polkit-docs - addressed in versions 0.112-26, 0.115-13
polkit - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
polkit-debuginfo - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
polkit-debugsource - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
typelib-1_0-Polkit-1_0 - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
libpolkit0-32bit - update to 0.113-5.24.1
libpolkit0-debuginfo-32bit - update to 0.113-5.24.1
polkit-devel - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
polkit-devel-debuginfo - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
libpolkit0-debuginfo - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
libpolkit0 - addressed in versions 0.113-5.24.1, 0.114-3.15.1, 0.116-3.6.1
polkit-libs - update to 0.115-13
polkit-help - update to 0.116-8
polkit-debuginfo - update to 0.116-8
polkit-devel - update to 0.116-8
polkit-libs - update to 0.116-8
polkit-debugsource - update to 0.116-8
polkit - update to 0.116-8
polkit - addressed in versions 0.117-3.fc34.2, 0.120-1.fc35.1
polkit - update to 0.117-10
wget (Red Hat package) - update to 1.19.5-10.el8
SCALANCE LPE9403 - update to 2.0
Aruba Analytics and Location Engine - update to 2.2.0.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.6
Aruba Central On-Premises - update to 2.5.4.3
SINUMERIK Edge - update to 3.3.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
RecoverPoint for VMs - update to 5.3.3
Session Smart Router - addressed in versions 5.4.7, 5.5.3
Disk Library for mainframe (DLm) - update to 5.5.0.0
XtremIO X2 - update to 6.4.2-13
ClearPass Policy Manager - addressed in versions 6.8.9 Hotfix 2, 6.9.10, 6.10.4
SCALANCE M804PB - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE S615 EEC - update to 7.2
Solutions Enabler Virtual Appliance - addressed in versions 9.1.0.19, 9.2.3.1
Solutions Enabler - addressed in versions 9.1.0.19, 9.2.3.1
Unisphere 360 - addressed in versions 9.1.0.30, 9.2.3.4
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.32, 9.2.3.11
Unisphere for PowerMax - addressed in versions 9.1.0.32, 9.2.3.11
VASA Provider Standalone - addressed in versions 9.1.0.724, 9.2.3.10
Connectrix MDS-DCNM - update to 11.5(4)
Contrail Networking - update to 2011.L5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins