There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
| Software | From | Fixed in |
|---|---|---|
| polkit_project / polkit | 0.117 | 0.117.x |
| redhat / enterprise_linux | 8.0 | 8.0.x |
| fedoraproject / fedora | 34 | 34.x |
| fedoraproject / fedora | 35 | 35.x |
| canonical / ubuntu_linux | 20.04 | 20.04.x |
| canonical / ubuntu_linux | 21.10 | 21.10.x |
| debian / debian_linux | 11.0 | 11.0.x |
| oracle / zfs_storage_appliance_kit | 8.8 | 8.8.x |