﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
11692	Create security patch for polkit (CVE-2019-6133)	Douglas R. Reno	Douglas R. Reno	"There is a security issue in polkit allowing for authentication bypass:

{{{
In PolicyKit (aka polkit) 0.115, the ""start time"" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
}}}

[https://gitlab.freedesktop.org/polkit/polkit/commit/c898fdf4b1aafaa04f8ada9d73d77c8bb76e2f81#0cf68d1183ea5299db7cd71b8377fa3d29e1a63e]"	enhancement	closed	high	8.4	BOOK	SVN	medium	fixed		
