Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-4034: polkit vulnerability #2756

Closed
miwithro opened this issue Jan 26, 2022 · 11 comments
Closed

CVE-2021-4034: polkit vulnerability #2756

miwithro opened this issue Jan 26, 2022 · 11 comments
Assignees

Comments

@miwithro
Copy link
Contributor

miwithro commented Jan 26, 2022

https://ubuntu.com/security/CVE-2021-4034

Local Privilege Escalation in polkit’s pkexec

AKS Information:

Update your node image to 2022.02.01 to remediate this vulnerability.

AKS
-- | --

@iggyemu
Copy link

iggyemu commented Jan 28, 2022

Hey AKS Team. Any update on this patch?

@miwithro
Copy link
Contributor Author

Yes this will be patched as part of the next release next week.

@therockvalley
Copy link

Yes this will be patched as part of the next release next week.

To confirm, does next week = the upcoming week (i.e. starting Jan 31)?

@iggyemu
Copy link

iggyemu commented Feb 3, 2022

AKS Team, today's AKS Release does not have the latest Polkit to remediate this CVE. It still reflects the vulnerable Polkit version of 18.04.5

image

It needs to be 18.04.6 according Ubuntu's recommendation: https://ubuntu.com/security/notices/USN-5252-1

image

When can we expect an update?

@miwithro
Copy link
Contributor Author

miwithro commented Feb 3, 2022

@iggyemu this issue is remediated in the release we just cut this week that will be released next week. 2022-02-01

@ChrisHolman
Copy link

Any update on this patch?

@miwithro
Copy link
Contributor Author

miwithro commented Feb 9, 2022

@ChrisHolman this issue is remediated in the release we just cut this week that will be released next week. 2022-02-01

@rouke-broersma
Copy link

@miwithro it already is next week per your previous exact same comment. Are you saying the release has been moved to next week or are you saying it will be released this week.

@miwithro
Copy link
Contributor Author

@rouke-broersma The VHD with the CVE fix will be rolled out to all regions by 2.16.

https://github.com/Azure/AKS/releases/tag/2022-02-06

@miwithro miwithro unpinned this issue Mar 9, 2022
@ghost ghost added the action-required label Mar 27, 2022
@ghost ghost added the stale Stale issue label May 26, 2022
@ghost
Copy link

ghost commented May 26, 2022

This issue has been automatically marked as stale because it has not had any activity for 60 days. It will be closed if no further activity occurs within 15 days of this comment.

@ghost ghost closed this as completed Jun 3, 2022
@ghost
Copy link

ghost commented Jun 3, 2022

This issue will now be closed because it hasn't had any activity for 7 days after stale. miwithro feel free to comment again on the next 7 days to reopen or open a new issue after that time if you still have a question/issue or suggestion.

@ghost ghost locked as resolved and limited conversation to collaborators Jul 3, 2022
This issue was closed.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

5 participants