
CVE-2021-4034 PwnKit: 12-Year polkit Flaw, Local Root
CVE-2021-4034, named PwnKit by Qualys, is an out-of-bounds write vulnerability in pkexec, a SUID-root binary part of the polkit framework installed by default on virtually every Linux distribution. Any local unprivileged user can exploit it to gain root without any sudo permissions, without knowing any password, and without triggering standard auth log entries. Present since May 2009.
