vmihalko / t2_polkit

Other
0 stars 0 forks source link

CVE-2021-4115: file descriptor leak allows an unprivileged user to cause a crash #174

Closed vmihalko closed 1 year ago

vmihalko commented 2 years ago

In GitLab by @smcv on Feb 18, 2022, 10:44

This doesn't appear to have been fixed (or even reported) upstream yet.

vmihalko commented 2 years ago

In GitLab by @smcv on Feb 18, 2022, 11:00

A patch is available via Fedora. I'm not providing a merge request right now because I don't know how to attribute it to an author. (Possibly @jrybar or Kevin Backhouse?)

vmihalko commented 2 years ago

In GitLab by @alanc on Feb 18, 2022, 20:21

According to https://securitylab.github.com/advisories/GHSL-2021-077-polkit/ this was reported as issue #141 here, but that's currently under restricted access.

vmihalko commented 2 years ago

In GitLab by @smcv on Feb 19, 2022, 24:14

Thanks, this is indeed the same issue as #141.

vmihalko commented 2 years ago

In GitLab by @jrybar on Feb 21, 2022, 09:07

Yeah, I had it prepped in confidential MR, but @halfline uncovered it while we already had weekend here in Europe.