Bug 1595404 (CVE-2018-1116)

Summary: CVE-2018-1116 polkit: Improper authorization in polkit_backend_interactive_authority_check_authorization function in polkitd
Product: [Other] Security Response Reporter: Laura Pardo <lpardo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: mitr, polkit-devel, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: polkit 0.116 Doc Type: If docs needed, set a value
Doc Text:
It was found that Polkit's CheckAuthorization and RegisterAuthenticationAgent D-Bus calls did not validate the client provided UID. A specially crafted program could use this flaw to submit arbitrary UIDs, triggering various denial of service or minor disclosures, such as which authentication is cached in the victim's session.
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-03-31 22:32:37 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1599790, 1599791, 1601411, 1829563, 1831063    
Bug Blocks: 1595405    

Description Laura Pardo 2018-06-26 20:45:29 UTC
A flaw was found in polkit. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

Comment 1 Cedric Buissart 2018-07-10 15:21:00 UTC
Upstream fix:
https://cgit.freedesktop.org/polkit/commit/?id=bc7ffad5364

Comment 2 Cedric Buissart 2018-07-10 15:21:22 UTC
Created polkit tracking bugs for this issue:

Affects: fedora-all [bug 1599790]

Comment 5 errata-xmlrpc 2020-03-31 19:27:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:1135 https://access.redhat.com/errata/RHSA-2020:1135

Comment 6 Product Security DevOps Team 2020-03-31 22:32:37 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2018-1116