CVE-2021-4034 (pwnkit)

Support for security such as Firewalls and securing linux
User avatar
jlehtone
Posts: 4530
Joined: 2007/12/11 08:17:33
Location: Finland

Re: CVE-2021-4034 (pwnkit)

Post by jlehtone » 2022/01/29 16:23:38

unimage wrote:
2022/01/27 18:34:38
So is the mitigation to simply install polkit-0.112-26.el7_9.1.src.rpm?
  • The *.src.rpm are source packages. The (binary) packages that are installed (x86_64, noarch, i686) are built from those sources.
  • If one needs to install polkit, then one did not have older version of polkit, and hence no vulnerability.
  • Generally yum update -- the update every installed package with anything that is available -- is the best practice. Cherry picking quickly creates a sour taste.

Yogesh_ab
Posts: 1
Joined: 2022/02/14 13:34:24

Re: CVE-2021-4034 (pwnkit)

Post by Yogesh_ab » 2022/02/14 13:41:36

Hi,

Do we have a security update for polkit package for CentOS 6 ?
From redhat site I can see an updated packages is polkit-0.96-11.el6_10.2.x86_64.rpm but that is available for Extended support only, do we have similar package version for CentOS also, if yes can someone please share an link to download the package.
Its a bit urgent request.

Thanks in advance

Regards,
Yogesh

User avatar
TrevorH
Site Admin
Posts: 33215
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CVE-2021-4034 (pwnkit)

Post by TrevorH » 2022/02/14 15:04:55

No. CentOS 6 has been End of Life for more than 1 year and no more updates will be issued.

If you are seeing errata on the Red Hat page for it then that is for the EUS (extended update support) version of RHEL which is a subscription offering and RH do not publish the source code for those. That makes it impossible for anyone outside RH to rebuild it.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Post Reply