CVE-2021-3560
Privilege escalation via race condition in polkit.
Vulnerability Description
CVE-2021-3560 is a race condition in polkit that allows an unauthenticated local user to gain root privileges. The vulnerability exists in the way polkit handles D-Bus errors when a connection is terminated.
Timing Determination
To determine the optimal timing, run the command:
time dbus-send --system --dest=org.freedesktop.Accounts --type=method_call --print-reply /org/freedesktop/Accounts org.freedesktop.Accounts.CreateUser string:testuser string:"Test User" int32:1
The code uses a range of half the real time ± 0.003.
Why is timing important?
- If the process is killed too early, the request will not be sent
- If killed too late, polkit will have time to check authorization and reject it
- You need to hit the "golden window" when polkit has already received the request but has not yet checked authorization
How does the exploit work?
- A D-Bus request is sent to create a user with the parameter int32:1 (adding to the wheel group)
- The request is interrupted mid-way (race condition)
- Polkit fails to complete the authorization check
- D-Bus cannot find the sender
- Polkit incorrectly handles the error and assigns UID = 0 (root)
- The user is created without authentication
- A request is sent to set a password for the new user (with the same timing)
Success Statistics
- The user can be created within 1-2 attempts
- Setting the password requires more attempts
- 100 iterations give a high probability of success
If the exploit does not work, try:
- Expand TIMING_RANGE in the code
- Run the script several times
- Make sure you are in an SSH session (not in a graphical one)