<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:15:29.635361+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:0267</id>
    <title>ALSA-2022:0267 — Important: polkit security update</title>
    <updated>2026-10-02T17:15:30.032872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: polkit, AlmaLinux:8: polkit-devel, AlmaLinux:8: polkit-docs, AlmaLinux:8: polkit-libs</p>
<p>The polkit packages provide a component for controlling system-wide privileges. This component provides a uniform and organized way for non-privileged processes to communicate with privileged ones.</p>
<p>Security Fix(es):</p>
<p>* polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector (CVE-2021-4034)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:0267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00488</id>
    <title>bdu:2022-00488</title>
    <updated>2026-10-02T17:15:30.032944+00:00</updated>
    <content>bdu:2022-00488</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00488"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-4034</id>
    <title>Withdrawn: BELL-CVE-2021-4034 — CVE-2021-4034 does not affect BellSoft software</title>
    <updated>2026-10-02T17:15:30.032961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-4034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-083</id>
    <title>certfr-2022-avi-083 — Une vulnérabilité a été découverte dans pkexec de PolicyKit sur Ubuntu.
Elle permet à un attaquant de provoquer une élé…</title>
    <updated>2026-10-02T17:15:30.032977+00:00</updated>
    <content>certfr-2022-avi-083</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-07226</id>
    <title>cnvd-2022-07226</title>
    <updated>2026-10-02T17:15:30.032991+00:00</updated>
    <content>cnvd-2022-07226</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-07226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352988</id>
    <title>EUVD-2026-352988</title>
    <updated>2026-10-02T17:15:30.033002+00:00</updated>
    <content>EUVD-2026-352988</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-4034</id>
    <title>fkie_cve-2021-4034</title>
    <updated>2026-10-02T17:15:30.033012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-4034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qgr2-xgqv-24x8</id>
    <title>GHSA-qgr2-xgqv-24x8</title>
    <updated>2026-10-02T17:15:30.033036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qgr2-xgqv-24x8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-4034</id>
    <title>gsd-2021-4034</title>
    <updated>2026-10-02T17:15:30.033053+00:00</updated>
    <content>gsd-2021-4034</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-4034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-167-16</id>
    <title>ICSA-22-167-16 — Siemens SCALANCE LPE 4903 and SINUMERIK Edge</title>
    <updated>2026-10-02T17:15:30.033063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-167-16"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-4034</id>
    <title>msrc_CVE-2021-4034 — A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid too…</title>
    <updated>2026-10-02T17:15:30.033084+00:00</updated>
    <content>msrc_CVE-2021-4034</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-4034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1502</id>
    <title>OESA-2022-1502 — polkit security update</title>
    <updated>2026-10-02T17:15:30.033102+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: polkit, openEuler:20.03-LTS-SP2: polkit, openEuler:20.03-LTS-SP3: polkit</p>
<p>Define and Handle authorizations tool.

Security Fix(es):

A local privilege escalation vulnerability was found on polkit&amp;apos;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;apos;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;apos;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.(CVE-2021-4034)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0190-1</id>
    <title>openSUSE-SU-2022:0190-1 — Security update for polkit</title>
    <updated>2026-10-02T17:15:30.033129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for polkit</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0190-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0265</id>
    <title>RHSA-2022:0265 — Red Hat Security Advisory: polkit security update</title>
    <updated>2026-10-02T17:15:30.033144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2022-0002</id>
    <title>SCA-2022-0002 — PwnKit vulnerability affects multiple SICK IPCs</title>
    <updated>2026-10-02T17:15:30.033159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>CVE-2021-4034 is a Local Privilege Escalation (LPE) vulnerability, located in the "Polkit" package 
installed by default on almost every major distribution of the Linux operating system.</p>
<p>On 2022-01-25, Qualys released an advisory for this LPE vulnerability, advising to either update the “Polkit” package or implement the mitigation that Qualys recommends.</p>
<p>In an air-gapped system SICK recommends all customers to implement at least the available mitigation for the corresponding Linux distribution. Please note, that this vulnerability can be exploited only if an user with unprivileged authorization can establish a connection to the systems.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2022-0002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0189-1</id>
    <title>SUSE-SU-2022:0189-1 — Security update for polkit</title>
    <updated>2026-10-02T17:15:30.033183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for polkit</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0189-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4034</id>
    <title>UBUNTU-CVE-2021-4034</title>
    <updated>2026-10-02T17:15:30.033204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: policykit-1, Ubuntu:Pro:16.04:LTS: policykit-1, Ubuntu:18.04:LTS: policykit-1, Ubuntu:20.04:LTS: policykit-1, Ubuntu:22.04:LTS: policykit-1</p>
<p>A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</id>
    <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
    <updated>2026-10-02T17:15:30.033262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302"/>
  </entry>
</feed>
