Related Vulnerabilities: CVE-2021-3560  

A security issue was found in polkit before version 0.119. When a requesting process disconnects from dbus-daemon just before the call to polkit_system_bus_name_get_creds_sync starts, the process cannot get a unique uid and pid of the process and it cannot verify the privileges of the requesting process.

Severity Medium

Remote No

Type Privilege escalation

Description

A security issue was found in polkit before version 0.119. When a requesting process disconnects from dbus-daemon just before the call to polkit_system_bus_name_get_creds_sync starts, the process cannot get a unique uid and pid of the process and it cannot verify the privileges of the requesting process.

AVG-2028 polkit 0.118-1 Medium Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1961710