Linux Root Vulnerability Undetected for 12 Years Affects All Major Distros

Stock image of a digital skull in code
(Image credit: Shutterstock)

Security researchers from Qualys have just discovered a 12-year-old Linux vulnerability that has remained undetected until now. The bug, dubbed PwnKit, allows hackers to gain full root privileges through an unprivileged user, thanks to a memory corruption vulnerability in polkit's pkexec. This is a SUID-root program installed on every major Linux distro.

According to the researchers, Polkit is a component for controlling privileges in Unix-like operating systems, including Linux distros. It effectively allows unprivileged processes to communicate with privileged processes currently running. If you are an administrator (or root) you can also use Polkit to push elevated commands if necessary.

Latest Videos FromTom's Hardware
Aaron Klotz
Contributing Writer

Aaron Klotz is a contributing writer for Tom’s Hardware, covering news related to computer hardware such as CPUs, and graphics cards.