Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Oracle Linux 8 ELSA-2022-1546 Moderate: Polkit Privilege Escalation Issue

oracle
Calendar Grey April 27, 2022
Oracle Linux Logo Esm H88
Oracle Linux 8 polkit security update addresses critical vulnerabilities to mitigate risks of privilege escalation and denial-of-service scenarios.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network

Summary

[0.115-13.0.1.el8_5.2] - Increase timeout to avoid defunct processes [Orabug: 26930744] [0.115-13.el8_5.2] - necessary version bump due to build versioning - Resolves: CVE-2021-4115 [0.115-12.el8_5.2] - file descriptor exhaustion (GHSL-2021-077) - Resolves: CVE-2021-4115 [0.115-12.el8_5.1] - pkexec: argv overflow results in local privilege esc. - Resolves: CVE-2021-4034 [0.115-12] - early disconnection from D-Bus results in privilege esc. - Resolves: CVE-2021-3560 [0.115-11] - pkttyagent: resetting terminal erases rest of input line - Resolves: rhbz#1757853 [0.115-10] - Fix of jasuthority memleak - Resolves: rhbz#1745918 [0.115-9] - Rebuild to reflect mozjs60 s390 abi change - Related: rhbz#1746889 [0.115-8] - Backport changing dependency to mozjs60 - Resolves: rhbz#1729416 [0.115-7] - pkttyagent: polkit-agent-helper-1 timeout leaves tty echo disabled - Mitigation of regression caused by fix of CVE-2018-19788 - Resolves: rhbz#1693781 ...

Read the Full Advisory

SRPMs

https://oss.oracle.com:443/ol8/SRPMS-updates/polkit-0.115-13.0.1.el8_5.2.src.rpm

x86_64

polkit-0.115-13.0.1.el8_5.2.x86_64.rpm polkit-devel-0.115-13.0.1.el8_5.2.i686.rpm polkit-devel-0.115-13.0.1.el8_5.2.x86_64.rpm polkit-docs-0.115-13.0.1.el8_5.2.noarch.rpm polkit-libs-0.115-13.0.1.el8_5.2.i686.rpm polkit-libs-0.115-13.0.1.el8_5.2.x86_64.rpm

aarch64

polkit-0.115-13.0.1.el8_5.2.aarch64.rpm polkit-devel-0.115-13.0.1.el8_5.2.aarch64.rpm polkit-docs-0.115-13.0.1.el8_5.2.noarch.rpm polkit-libs-0.115-13.0.1.el8_5.2.aarch64.rpm

Related CVEs: CVE-2021-4115

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here