VulnerabilityModified
CVE-2019-6133
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached.
MEDIUM 6.7EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
- CVSS 3.0
- 6.7 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- polkit project/polkit · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00049.html
- http://www.securityfocus.com/bid/106537Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0230Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0420Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0832Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2699
- https://access.redhat.com/errata/RHSA-2019:2978
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1692Issue Tracking, Mailing List, Third Party Advisory
- https://git.kernel.org/linus/7b55851367136b1efd84d98fea81ba57a98304cfPatch, Third Party Advisory
- https://gitlab.freedesktop.org/polkit/polkit/commit/c898fdf4b1aafaa04f8ada9d73d77c8bb76e2f81Patch, Third Party Advisory
- https://gitlab.freedesktop.org/polkit/polkit/merge_requests/19Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00021.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00041.html
- https://lists.debian.org/debian-lts-announce/2019/05/msg00042.html
- https://support.f5.com/csp/article/K22715344Third Party Advisory
- https://usn.ubuntu.com/3901-1/Third Party Advisory
- https://usn.ubuntu.com/3901-2/Third Party Advisory
- https://usn.ubuntu.com/3903-1/Third Party Advisory
- https://usn.ubuntu.com/3903-2/Third Party Advisory
- https://usn.ubuntu.com/3908-1/Third Party Advisory
- https://usn.ubuntu.com/3908-2/Third Party Advisory
- https://usn.ubuntu.com/3910-1/Third Party Advisory
- https://usn.ubuntu.com/3910-2/Third Party Advisory
- https://usn.ubuntu.com/3934-1/Third Party Advisory
- https://usn.ubuntu.com/3934-2/
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00049.html
- http://www.securityfocus.com/bid/106537Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0230Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0420Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0832Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.