Pardus Linux Local Privilege Escalation Flaw Allows Silent Root Access
ID: 93fd4f28-0c7f-5485-814f-888efd9f5318
STIX ID: report--93fd4f28-0c7f-5485-814f-888efd9f5318
Feed Name: cybersecurityNews.com
A critical privilege-escalation chain in the pardus-update package (CVSS v3.1 9.3) allows local users to gain root without authentication. The issue combines: (1) a Polkit policy configured with allow_any=yes permitting passwordless privileged actions; (2) a CRLF injection in SystemSettingsWrite.py that lets attackers add attacker-controlled APT source entries; and (3) AutoAptUpgrade.py copying untrusted APT source files into /etc/apt/sources.list.d/, enabling installation of a malicious .deb. A PoC demonstrates installing a package that sets the SUID bit on /bin/bash, yielding an immediate root shell. Recommended mitigations are to require administrator authentication in the Polkit policy, sanitize carriage returns/newlines in input handling, and restrict APT source file paths to trusted directories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
