View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0009350 | Kali Linux | Kali Package Bug | public | 2025-10-11 11:09 | 2025-10-11 21:42 |
Reporter | Abodavidjr | Assigned To | |||
Priority | normal | Severity | minor | Reproducibility | have not tried |
Status | new | Resolution | open | ||
Summary | 0009350: Critical Authentication Bypass in Kali Linux PolicyKit - Unauthorized Root File Access | ||||
Description | Critical Authentication Bypass in Kali Linux PolicyKitSystem Information
Vulnerability SummaryA critical security bypass vulnerability exists in Kali Linux's PolicyKit authentication mechanism that allows unprivileged users to access sensitive system files without proper authentication by repeatedly pressing the Cancel button in authentication dialogs. Steps to Reproduce
Proof of Compromise - Files Successfully AccessedNetwork Configuration:
System Security Files:
System Configuration:
Kernel and Log Files:
Impact AssessmentRisk Level: CRITICAL
Technical Details
Additional Notes
Recommended Actions
| ||||
Attached Files | |||||
Maybe you are not aware but all of the mentioned files are ready only for any user on a Linux system on most/every Linux system independent if Kali. They just don't contain any sensitive information. The only mentioned sensitive file is the following:
which is not accessible and which proofs that there is no auth bypass involved at all. |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2025-10-11 11:09 | Abodavidjr | New Issue | |
2025-10-11 11:09 | Abodavidjr | File Added: buge-kali3.JPG | |
2025-10-11 11:09 | Abodavidjr | File Added: bug-kali1.JPG | |
2025-10-11 11:09 | Abodavidjr | File Added: bug-kali2..JPG | |
2025-10-11 21:42 | kali-bugreport | Note Added: 0020882 |