CVE-2021-4034 (pwnkit)

Support for security such as Firewalls and securing linux
Post Reply
green63
Posts: 1
Joined: 2022/01/28 11:27:12

CVE-2021-4034 (pwnkit)

Post by green63 » 2022/01/28 11:30:39

With the recent polkit root compromise vulnerability, do you know when centOS 8 will release the updated polkit package?
RHEL has it available already.

User avatar
TrevorH
Site Admin
Posts: 33202
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CVE-2021-4034 (pwnkit)

Post by TrevorH » 2022/01/28 11:34:52

Never. CentOS 8 is EOL as of the end of 2021.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

User avatar
jlehtone
Posts: 4523
Joined: 2007/12/11 08:17:33
Location: Finland

Re: CVE-2021-4034 (pwnkit)

Post by jlehtone » 2022/01/28 12:31:28

The CentOS Stream 8 has apparently built polkit last Wednesday.

The "centOS 8" is ambiguous, because you could mean "CentOS Linux 8" that is very dead now, or "CentOS Stream 8", which is not while Red Hat has still a future RHEL 8 point update to assemble.
https://www.centos.org/cl-vs-cs/

See also: https://www.centos.org/centos-linux-eol/


AlmaLinux and Rocky Linux did release fresh polkit in timely manner too.

spawarbabu
Posts: 3
Joined: 2022/01/30 11:33:59

Re: CVE-2021-4034 (pwnkit)

Post by spawarbabu » 2022/01/30 11:46:19

Can we get for Centos 6 by any chance as RHEL is offering the updated package of policykit

User avatar
TrevorH
Site Admin
Posts: 33202
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CVE-2021-4034 (pwnkit)

Post by TrevorH » 2022/01/30 13:13:39

CentOS 6 has been dead for more than 1 year now. No more updates will be released for it.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Post Reply