Wind River Support Network

HomeDefectsLIN1021-485
Fixed

LIN1021-485 : Security Advisory - polkit - CVE-2021-3560

Created: Jun 3, 2021    Updated: Mar 7, 2022
Resolved Date: Sep 9, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.5
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

polkit: local privilege escalation using polkit_system_bus_name_get_creds_sync()

Upstream fix :
https://gitlab.freedesktop.org/polkit/polkit/-/commit/a04d13affe0fa53ff618e07aa8f57f4c0e3b9b81

CREATE(Triage):(User=admin) CVE-2021-3560 (https://nvd.nist.gov/vuln/detail/CVE-2021-3560)

CVEs


Live chat
Online