Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

CVSS v2 metrics

Base Score 6.9
Base Metrics AV:L/AC:M/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (polkit) RHSA-2013:1270 2013-09-19

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 polkit Not affected


Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for reporting this issue.