<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:37:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:0267 — Important: polkit security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:0267</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: polkit, AlmaLinux:8: polkit-devel, AlmaLinux:8: polkit-docs, AlmaLinux:8: polkit-libs&lt;/p&gt;
&lt;p&gt;The polkit packages provide a component for controlling system-wide privileges. This component provides a uniform and organized way for non-privileged processes to communicate with privileged ones.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector (CVE-2021-4034)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: polkit, AlmaLinux:8: polkit-devel, AlmaLinux:8: polkit-docs, AlmaLinux:8: polkit-libs&lt;/p&gt;
&lt;p&gt;The polkit packages provide a component for controlling system-wide privileges. This component provides a uniform and organized way for non-privileged processes to communicate with privileged ones.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector (CVE-2021-4034)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:0267</guid>
    </item>
    <item>
      <title>bdu:2022-00488</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00488</link>
      <description>bdu:2022-00488</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00488</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-4034 — CVE-2021-4034 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-4034</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-4034</guid>
    </item>
    <item>
      <title>certfr-2022-avi-083 — Une vulnérabilité a été découverte dans pkexec de PolicyKit sur Ubuntu.
Elle permet à un attaquant de provoquer une élé…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-083</link>
      <description>certfr-2022-avi-083</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-083</guid>
    </item>
    <item>
      <title>cnvd-2022-07226</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-07226</link>
      <description>cnvd-2022-07226</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-07226</guid>
    </item>
    <item>
      <title>EUVD-2026-352988</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352988</link>
      <description>EUVD-2026-352988</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352988</guid>
    </item>
    <item>
      <title>fkie_cve-2021-4034</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-4034</link>
      <description>&lt;p&gt;A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-4034</guid>
    </item>
    <item>
      <title>GHSA-qgr2-xgqv-24x8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qgr2-xgqv-24x8</link>
      <description>&lt;p&gt;A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qgr2-xgqv-24x8</guid>
    </item>
    <item>
      <title>gsd-2021-4034</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-4034</link>
      <description>gsd-2021-4034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-4034</guid>
    </item>
    <item>
      <title>ICSA-22-167-16 — Siemens SCALANCE LPE 4903 and SINUMERIK Edge</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-167-16</link>
      <description>&lt;p&gt;A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-167-16</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-4034 — A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid too…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-4034</link>
      <description>msrc_CVE-2021-4034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-4034</guid>
    </item>
    <item>
      <title>OESA-2022-1502 — polkit security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: polkit, openEuler:20.03-LTS-SP2: polkit, openEuler:20.03-LTS-SP3: polkit&lt;/p&gt;
&lt;p&gt;Define and Handle authorizations tool.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A local privilege escalation vulnerability was found on polkit&amp;amp;apos;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;amp;apos;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;amp;apos;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.(CVE-2021-4034)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: polkit, openEuler:20.03-LTS-SP2: polkit, openEuler:20.03-LTS-SP3: polkit&lt;/p&gt;
&lt;p&gt;Define and Handle authorizations tool.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A local privilege escalation vulnerability was found on polkit&amp;amp;apos;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;amp;apos;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;amp;apos;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.(CVE-2021-4034)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1502</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0190-1 — Security update for polkit</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0190-1</link>
      <description>&lt;p&gt;Security update for polkit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for polkit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0190-1</guid>
    </item>
    <item>
      <title>RHSA-2022:0265 — Red Hat Security Advisory: polkit security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0265</link>
      <description>&lt;p&gt;polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;polkit: Local privilege escalation in pkexec due to incorrect handling of argument vector&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0265</guid>
    </item>
    <item>
      <title>SCA-2022-0002 — PwnKit vulnerability affects multiple SICK IPCs</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2022-0002</link>
      <description>&lt;p&gt;CVE-2021-4034 is a Local Privilege Escalation (LPE) vulnerability, located in the &amp;#34;Polkit&amp;#34; package 
installed by default on almost every major distribution of the Linux operating system.&lt;/p&gt;
&lt;p&gt;On 2022-01-25, Qualys released an advisory for this LPE vulnerability, advising to either update the “Polkit” package or implement the mitigation that Qualys recommends.&lt;/p&gt;
&lt;p&gt;In an air-gapped system SICK recommends all customers to implement at least the available mitigation for the corresponding Linux distribution. Please note, that this vulnerability can be exploited only if an user with unprivileged authorization can establish a connection to the systems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CVE-2021-4034 is a Local Privilege Escalation (LPE) vulnerability, located in the &amp;#34;Polkit&amp;#34; package 
installed by default on almost every major distribution of the Linux operating system.&lt;/p&gt;
&lt;p&gt;On 2022-01-25, Qualys released an advisory for this LPE vulnerability, advising to either update the “Polkit” package or implement the mitigation that Qualys recommends.&lt;/p&gt;
&lt;p&gt;In an air-gapped system SICK recommends all customers to implement at least the available mitigation for the corresponding Linux distribution. Please note, that this vulnerability can be exploited only if an user with unprivileged authorization can establish a connection to the systems.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2022-0002</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0189-1 — Security update for polkit</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0189-1</link>
      <description>&lt;p&gt;Security update for polkit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for polkit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0189-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-4034</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4034</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: policykit-1, Ubuntu:Pro:16.04:LTS: policykit-1, Ubuntu:18.04:LTS: policykit-1, Ubuntu:20.04:LTS: policykit-1, Ubuntu:22.04:LTS: policykit-1&lt;/p&gt;
&lt;p&gt;A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: policykit-1, Ubuntu:Pro:16.04:LTS: policykit-1, Ubuntu:18.04:LTS: policykit-1, Ubuntu:20.04:LTS: policykit-1, Ubuntu:22.04:LTS: policykit-1&lt;/p&gt;
&lt;p&gt;A local privilege escalation vulnerability was found on polkit&amp;#39;s pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn&amp;#39;t handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it&amp;#39;ll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4034</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</guid>
    </item>
  </channel>
</rss>
