angler-fishThe Vulnerability History Project

polkit: Avoid race condition in scraping /proc

      If a calling process execve()s a setuid program, it can appear to be
uid 0.  Since we're receiving requests over DBus, avoid this by simply
passing system-bus-name as a subject.
    
commit 72fd713962ca2c2450e23b01d9e22017a7e28fd4
+26 -5
expand_less