USN-3934-1
Not scored
policykit-1 vulnerability
It was discovered that PolicyKit incorrectly relied on the fork() system call in the Linux kernel being atomic. A local attacker could possibly use this issue to gain access to services that have cached authorizations.
Exploit probability
Not scored
Published
April 3, 2019
Required by
Not available
Last source change
April 22, 2026
02 / AFFECTED SOFTWARE
Affected packages
7 explicit affected versions
7 explicit affected versions
4 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
USN-3934-1
View original source
It was discovered that PolicyKit incorrectly relied on the fork() system call in the Linux kernel being atomic. A local attacker could possibly use this issue to gain access to services that have cached authorizations.
05 / REFERENCES