CVE-2019-6133: Canonical Ubuntu Linux

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only
  • Polkit Project Polkit: version 0.115 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only; version 6.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only; version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only; version 6.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only; version 6.0 only

Published 2019-01-11. Last modified 2026-06-17.