Researchers find a 12-year-old vulnerability in Polkit that local attackers can use to gain root privileges on all major Linux distributions; an exploit is out
BleepingComputerIonut Ilascu
Context & Ripple Effects
This is the latest entry in a recurring pattern the coverage has tracked since at least 2016, when researchers disclosed an almost three-year-old privilege escalation bug in the Linux kernel imperiling PCs, servers, and Android phones, followed months later by a nine-year-old kernel privilege-escalation bug that shipped with an official patch. The common thread: core components of the Linux privilege model quietly carrying exploitable flaws for a decade or more before anyone looks.
What makes this disclosure different is Polkit itself — a component present across all major distributions rather than one kernel version — combined with a public exploit already in the wild, which compresses the window between disclosure and mass exploitation from weeks to hours.
First-order effects
Every major Linux distribution must ship emergency Polkit patches, and any multi-user system — servers, shared hosts, containers — is exposed right now because any local account can escalate to root using the public exploit.
Distro security teams and sysadmins are forced into triage mode: identify every machine running unpatched Polkit, since the bug predates a decade of installed systems and no configuration change reliably closes it.
Second-order effects
Enterprises that treated Linux as low-maintenance on endpoint hardening face the same patch-sprint cadence Windows admins know well, pushing vendors of Linux server management tooling to emphasize rapid component-level updates.
Security auditors will re-rank old, ubiquitous system components as attack surface, driving new scanning demand specifically for long-lived setuid-adjacent utilities like Polkit rather than just the kernel.
Third-order effects
If the pattern holds — three-year-old, nine-year-old, and now twelve-year-old privilege bugs in core plumbing — the industry's assumption that age equals stability in foundational Linux components inverts, favoring continuous fuzzing and memory-safe rewrites of privileged helpers.
Distributions may converge on faster coordinated-disclosure pipelines for shared components, since a flaw in one cross-distro library effectively sets the patch clock for every vendor simultaneously.
The trend: Linux security is shifting from treating the kernel as the main attack surface to auditing the decade-old privileged helper components every distribution ships, as researchers keep finding root-level bugs that predate entire product generations.
#CVE-2021-4034 in a system tool called Polkit has me concerned. Easy and reliable privilege escalation preinstalled on every major Linux distribution. Patch ASAP or use the simple chmod 0755 /usr/bin/pkexec mitigation. There are working POCs in the wild. https://arstechnica.com/.…
Fortunately, Linux is not used in any mission critical systems, like self-driving cars and AI-based medical diagnostics, so no problem...oh...wait... https://arstechnica.com/...
A 12-year-old, easy-to-exploit Linux bug gives attackers root privilege on machines running any major distribution of the operating system. https://arstechnica.com/...
root exploits on Linux are not a big deal. I have told people for ages that if someone gets on a Linux box you just need to assume the got root and proceed accordingly. In fact, just assume any intruder is admin on any compromised OS. It's easier to deal with reality this way. ht…
Still working late, this week is cursed. Woke up before my alarm to a new flurry of message notifications - plus, there's a new widespread Linux vulnerability (linked fyi). How is it only Wednesday. https://blog.qualys.com/...
New from Qualys: Memory corruption in a SUID-root program installed by default on every major Linux distribution. Easy to exploit, allows unprivileged user to gain full root privileges on a vulnerable host by exploiting vuln in its default configuration https://blog.qualys.com/..…
Probably a good day to take a look at your Linux systems. If there's no patch available for the OS, a simple chmod provides a pretty effective mitigation. https://blog.qualys.com/...
No, we need hardware which securely supports the architectural model we write our code against. Good news: It exists now: https://msrc-blog.microsoft.com/ ... https://twitter.com/...
> Therefore: > > at line 534, the integer n is permanently set to 1; > at line 610, the pointer path is read out-of-bounds from argv[1]; > at line 639, the pointer s is written out-of-bounds to argv[1]. I'm gonna fucking S C R E A M . https://twitter.com/...