USN-4980-1: polkit vulnerability
3 June 2021
The system could be made to run programs as an administrator.
Releases
Packages
- policykit-1 - framework for managing administrative policies and privileges
Details
Kevin Backhouse discovered that polkit incorrectly handled errors in the
polkit_system_bus_name_get_creds_sync function. A local attacker could
possibly use this issue to escalate privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 21.04
-
libpolkit-agent-1-0
-
0.105-30ubuntu0.1
-
libpolkit-gobject-1-0
-
0.105-30ubuntu0.1
-
policykit-1
-
0.105-30ubuntu0.1
Ubuntu 20.10
-
libpolkit-agent-1-0
-
0.105-29ubuntu0.1
-
libpolkit-gobject-1-0
-
0.105-29ubuntu0.1
-
policykit-1
-
0.105-29ubuntu0.1
Ubuntu 20.04
-
libpolkit-agent-1-0
-
0.105-26ubuntu1.1
-
libpolkit-gobject-1-0
-
0.105-26ubuntu1.1
-
policykit-1
-
0.105-26ubuntu1.1
After a standard system update you need to reboot your computer to make
all the necessary changes.