软件包中的 将 Unix 进程 polkit 主体的 uid 字段编码为无符号 32 位整数(D-Bus 类型 ),而 接口规范要求的是有符号 32 位整数(D-Bus 类型 )。由于存在这种类型不匹配,polkit 会静默丢弃调用方提供的 UID,并转而通过查询 中的 PID 来自主确定主体所有者,而该查询过程天然存在检查时/使用时(TOCTOU,Time-of-Check/Time-of-Use)竞争条件。 因此,即便应用程序从一个可靠来源(例如通过 Unix 套接字的 对端凭据)获取并传入一个 UID,试图防
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| z-galaxy | zbus_polkit | < 5.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| z-galaxy | zbus_polkit | 0 ~ 5.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet