{"id":"CVE-2021-4115","details":"There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned","modified":"2026-07-08T06:01:25.618107479Z","published":"2022-02-21T22:15:07.743Z","related":["ALSA-2022:1546","SUSE-SU-2022:0524-1","SUSE-SU-2022:0525-1","SUSE-SU-2022:0525-2","openSUSE-SU-2022:0525-1","openSUSE-SU-2024:11868-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:21.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"20.04"},{"last_affected":"20.04"},{"introduced":"21.10"},{"last_affected":"21.10"}]},{"cpes":["cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"11.0"},{"last_affected":"11.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"extracted_events":[{"introduced":"34"},{"last_affected":"34"},{"introduced":"35"},{"last_affected":"35"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.8"},{"last_affected":"8.8"}],"source":"CPE_STRING","vendor_product":"oracle:zfs_storage_appliance_kit"},{"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux","cpes":["cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/172849/polkit-File-Descriptor-Exhaustion.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VGKWCBS6IDZYYDYM2WIWJM5BL7QQTWPF/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/cve-2021-4115"},{"type":"FIX","url":"https://gitlab.com/redhat/centos-stream/rpms/polkit/-/merge_requests/6/diffs?commit_id=bf900df04dc390d389e59aa10942b0f2b15c531e"},{"type":"FIX","url":"https://gitlab.freedesktop.org/polkit/polkit/-/issues/141"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/polkit/polkit","events":[{"introduced":"585f4f2715639394e36319d4918389d26e250e7b"},{"last_affected":"585f4f2715639394e36319d4918389d26e250e7b"}],"database_specific":{"cpe":"cpe:2.3:a:polkit_project:polkit:0.117:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.117"},{"last_affected":"0.117"}],"source":"CPE_STRING"}}],"versions":["0.117"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-4115.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}