PwnKit bug endangers Linux distributions worldwide
Summary
A newly reported memory corruption vulnerability in a SUID-root program installed by default on every major Linux distribution worldwide can be easily exploited to give an unauthorised user full root privileges on a vulnerable host. The bug, tracked as CVE-2021-4034 and named PwnKit, was uncovered by Qualys researchers towards the end of 2021, but has apparently been hiding “in plain sight” since May 2009. Qualys security researchers have been able to independently verify the vulnerability, develop an exploit and obtain full root privileges on default installations of Ubuntu, Debian, Fedora and CentOS. A malicious actor can exploit this by crafting environment variables to force pkexec to execute arbitrary code and escalate their privileges. Patches for PwnKit are already dropping – Red Hat and Ubuntu users can find out more here and here, respectively – and polkit’s writers have made a patch available on GitHub, but Jogi warned that the vulnerability is likely to be exploited by malicious actors imminently.