ArchLinux: 201901-2: polkit: privilege escalation
Summary
A security issue has been found in polkit <= 0.115, where an unprivileged user with a UID > INT_MAX can successfully execute any systemctl command.
Resolution
Upgrade to 0.115+24+g5230646-1.
# pacman -Syu "polkit>=0.115+24+g5230646-1"
The problem has been fixed upstream but no release is available yet.
References
https://seclists.org/oss-sec/2018/q4/198 https://gitlab.freedesktop.org/polkit/polkit/-/issues/74 https://gitlab.freedesktop.org/polkit/polkit/-/commit/2cb40c4d5feeaa09325522bd7d97910f1b59e379 https://security.archlinux.org/CVE-2018-19788
Workaround
None.