Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2021-4115

Quick assessment

Affected
n/a polkitd
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

polkit是一个在类 Unix操作系统中控制系统范围权限的组件。通过定义和审核权限规则,实现不同优先级进程间的通讯。 polkit 存在资源管理错误漏洞,该漏洞源于进程文件描述符耗尽,攻击者利用该漏洞允许非特权用户导致polkit崩溃。

AI Predicted 5.3 Difficulty: Easy EPSS 0.53% · P43

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-4115

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5
Vulnerability Title
polkit 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
polkit是一个在类 Unix操作系统中控制系统范围权限的组件。通过定义和审核权限规则,实现不同优先级进程间的通讯。 polkit 存在资源管理错误漏洞,该漏洞源于进程文件描述符耗尽,攻击者利用该漏洞允许非特权用户导致polkit崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- polkitd 0.117 -

II. Public POCs for CVE-2021-4115

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-4115

登录查看更多情报信息。

Vendor Advisories for CVE-2021-4115 (2)

Exploits & Public PoCs for CVE-2021-4115 (1)

Mailing List Discussions for CVE-2021-4115 (1)

Other References for CVE-2021-4115 (2)

Same Patch Batch · n/a · 2022-02-21 · 12 CVEs total

CVE-2022-25297 7.5 HIGH Arbitrary File Write
CVE-2021-44141 samba 后置链接漏洞
CVE-2022-0563 util-linux 安全漏洞
CVE-2021-45008 Plesk Cms 访问控制错误漏洞
CVE-2022-24553 Zfaka 代码问题漏洞
CVE-2021-44568 libsolv 缓冲区错误漏洞
CVE-2021-27753 HCL Sametime 路径遍历漏洞
CVE-2021-27755 HCL Sametime 安全漏洞
CVE-2021-27796 Brocade Fabric OS 安全漏洞
CVE-2021-27797 Brocade Fabric OS 信任管理问题漏洞
CVE-2022-24564 Checkmk 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-4115

No comments yet


Leave a comment