{"id":"CVE-2021-4115","details":"There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned","modified":"2026-04-16T04:39:20.177039355Z","published":"2022-02-21T22:15:07.743Z","related":["ALSA-2022:1546","SUSE-SU-2022:0524-1","SUSE-SU-2022:0525-1","SUSE-SU-2022:0525-2","openSUSE-SU-2022:0525-1","openSUSE-SU-2024:11868-1"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VGKWCBS6IDZYYDYM2WIWJM5BL7QQTWPF/"},{"type":"WEB","url":"http://packetstormsecurity.com/files/172849/polkit-File-Descriptor-Exhaustion.html"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/cve-2021-4115"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"FIX","url":"https://gitlab.com/redhat/centos-stream/rpms/polkit/-/merge_requests/6/diffs?commit_id=bf900df04dc390d389e59aa10942b0f2b15c531e"},{"type":"FIX","url":"https://gitlab.freedesktop.org/polkit/polkit/-/issues/141"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/polkit/polkit","events":[{"introduced":"0"},{"last_affected":"585f4f2715639394e36319d4918389d26e250e7b"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"0.117"}]}}],"versions":["0.100","0.101","0.102","0.103","0.104","0.105","0.106","0.107","0.108","0.109","0.110","0.111","0.112","0.113","0.114","0.115","0.116","0.117","0.91","0.92","0.93","0.94","0.95","0.96","0.97","0.98","0.99","POLICY_KIT_0_3","POLICY_KIT_0_4","POLICY_KIT_0_5","POLICY_KIT_0_6","POLICY_KIT_0_7","POLICY_KIT_0_8","POLICY_KIT_0_9","start"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-4115.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"34"}]},{"events":[{"introduced":"0"},{"last_affected":"35"}]},{"events":[{"introduced":"0"},{"last_affected":"20.04"}]},{"events":[{"introduced":"0"},{"last_affected":"21.10"}]},{"events":[{"introduced":"0"},{"last_affected":"11.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.8"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}