zincati
Activity
- Latest release
- 7mo ago
- Total releases
- 31
- Cadence
- ~37 days
- Last 12 months
- 2
Details
- License
- Apache-2.0
- First release
- Jun 14, 2019
| Version | Released | |
|---|---|---|
0.0.32
unknown
|
0.0.32
unknown
Dependencies (42)
+ 34 more |
|
0.0.31
unknown
|
0.0.31
unknown
Dependencies (42)
+ 34 more |
|
0.0.30
unknown
|
0.0.30
unknown
Dependencies (42)
+ 34 more |
|
0.0.29
unknown
1 CVE
CVE-2025-27512
GHSA-w6fv-6gcc-x825
Mar 17, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
Local
Low
None
None
ImpactZincati ships a polkit rule which allows the
Since Zincati v0.0.24, this polkit rule contains a logic error which broadens access of those polkit actions to any unprivileged user rather than just the In practice, this means that any unprivileged user with access to the system D-Bus socket is able to deploy older Fedora CoreOS versions (which may have other known vulnerabilities). Note that rpm-ostree enforces that the selected version must be from the same branch the system is currently on so this cannot directly be used to deploy an attacker-controlled update payload. This primarily impacts users running untrusted workloads with access to the system D-Bus socket. Note that in general, untrusted workloads should not be given this access, whether containerized or not. By default, containers do not have access to the system D-Bus socket. PatchesThe logic error is fixed in Zincati v0.0.30. The fix is included in the following FCOS releases:
WorkaroundsA workaround is to add the following polkit rule:
to e.g. Note that this rule will deny all non-root users other than ReferencesThis issue was introduced by this commit, and is fixed in v0.0.30. Fixed in
0.0.30
References
Updated Mar 19, 2025 · Source: OSV.dev |
0.0.29
unknown
Dependencies (41)
+ 33 more |
|
0.0.28
unknown
1 CVE
CVE-2025-27512
GHSA-w6fv-6gcc-x825
Mar 17, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
Local
Low
None
None
ImpactZincati ships a polkit rule which allows the
Since Zincati v0.0.24, this polkit rule contains a logic error which broadens access of those polkit actions to any unprivileged user rather than just the In practice, this means that any unprivileged user with access to the system D-Bus socket is able to deploy older Fedora CoreOS versions (which may have other known vulnerabilities). Note that rpm-ostree enforces that the selected version must be from the same branch the system is currently on so this cannot directly be used to deploy an attacker-controlled update payload. This primarily impacts users running untrusted workloads with access to the system D-Bus socket. Note that in general, untrusted workloads should not be given this access, whether containerized or not. By default, containers do not have access to the system D-Bus socket. PatchesThe logic error is fixed in Zincati v0.0.30. The fix is included in the following FCOS releases:
WorkaroundsA workaround is to add the following polkit rule:
to e.g. Note that this rule will deny all non-root users other than ReferencesThis issue was introduced by this commit, and is fixed in v0.0.30. Fixed in
0.0.30
References
Updated Mar 19, 2025 · Source: OSV.dev |
0.0.28
unknown
Dependencies (41)
+ 33 more |
|
0.0.27
unknown
1 CVE
CVE-2025-27512
GHSA-w6fv-6gcc-x825
Mar 17, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
Local
Low
None
None
ImpactZincati ships a polkit rule which allows the
Since Zincati v0.0.24, this polkit rule contains a logic error which broadens access of those polkit actions to any unprivileged user rather than just the In practice, this means that any unprivileged user with access to the system D-Bus socket is able to deploy older Fedora CoreOS versions (which may have other known vulnerabilities). Note that rpm-ostree enforces that the selected version must be from the same branch the system is currently on so this cannot directly be used to deploy an attacker-controlled update payload. This primarily impacts users running untrusted workloads with access to the system D-Bus socket. Note that in general, untrusted workloads should not be given this access, whether containerized or not. By default, containers do not have access to the system D-Bus socket. PatchesThe logic error is fixed in Zincati v0.0.30. The fix is included in the following FCOS releases:
WorkaroundsA workaround is to add the following polkit rule:
to e.g. Note that this rule will deny all non-root users other than ReferencesThis issue was introduced by this commit, and is fixed in v0.0.30. Fixed in
0.0.30
References
Updated Mar 19, 2025 · Source: OSV.dev |
0.0.27
unknown
Dependencies (41)
+ 33 more |
|
0.0.26
unknown
1 CVE
CVE-2025-27512
GHSA-w6fv-6gcc-x825
Mar 17, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
Local
Low
None
None
ImpactZincati ships a polkit rule which allows the
Since Zincati v0.0.24, this polkit rule contains a logic error which broadens access of those polkit actions to any unprivileged user rather than just the In practice, this means that any unprivileged user with access to the system D-Bus socket is able to deploy older Fedora CoreOS versions (which may have other known vulnerabilities). Note that rpm-ostree enforces that the selected version must be from the same branch the system is currently on so this cannot directly be used to deploy an attacker-controlled update payload. This primarily impacts users running untrusted workloads with access to the system D-Bus socket. Note that in general, untrusted workloads should not be given this access, whether containerized or not. By default, containers do not have access to the system D-Bus socket. PatchesThe logic error is fixed in Zincati v0.0.30. The fix is included in the following FCOS releases:
WorkaroundsA workaround is to add the following polkit rule:
to e.g. Note that this rule will deny all non-root users other than ReferencesThis issue was introduced by this commit, and is fixed in v0.0.30. Fixed in
0.0.30
References
Updated Mar 19, 2025 · Source: OSV.dev |
0.0.26
unknown
Dependencies (41)
+ 33 more |
|
0.0.25
unknown
1 CVE
CVE-2025-27512
GHSA-w6fv-6gcc-x825
Mar 17, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
Local
Low
None
None
ImpactZincati ships a polkit rule which allows the
Since Zincati v0.0.24, this polkit rule contains a logic error which broadens access of those polkit actions to any unprivileged user rather than just the In practice, this means that any unprivileged user with access to the system D-Bus socket is able to deploy older Fedora CoreOS versions (which may have other known vulnerabilities). Note that rpm-ostree enforces that the selected version must be from the same branch the system is currently on so this cannot directly be used to deploy an attacker-controlled update payload. This primarily impacts users running untrusted workloads with access to the system D-Bus socket. Note that in general, untrusted workloads should not be given this access, whether containerized or not. By default, containers do not have access to the system D-Bus socket. PatchesThe logic error is fixed in Zincati v0.0.30. The fix is included in the following FCOS releases:
WorkaroundsA workaround is to add the following polkit rule:
to e.g. Note that this rule will deny all non-root users other than ReferencesThis issue was introduced by this commit, and is fixed in v0.0.30. Fixed in
0.0.30
References
Updated Mar 19, 2025 · Source: OSV.dev |
0.0.25
unknown
Dependencies (39)
+ 31 more |
|
0.0.24
unknown
1 CVE
CVE-2025-27512
GHSA-w6fv-6gcc-x825
Mar 17, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
Local
Low
None
None
ImpactZincati ships a polkit rule which allows the
Since Zincati v0.0.24, this polkit rule contains a logic error which broadens access of those polkit actions to any unprivileged user rather than just the In practice, this means that any unprivileged user with access to the system D-Bus socket is able to deploy older Fedora CoreOS versions (which may have other known vulnerabilities). Note that rpm-ostree enforces that the selected version must be from the same branch the system is currently on so this cannot directly be used to deploy an attacker-controlled update payload. This primarily impacts users running untrusted workloads with access to the system D-Bus socket. Note that in general, untrusted workloads should not be given this access, whether containerized or not. By default, containers do not have access to the system D-Bus socket. PatchesThe logic error is fixed in Zincati v0.0.30. The fix is included in the following FCOS releases:
WorkaroundsA workaround is to add the following polkit rule:
to e.g. Note that this rule will deny all non-root users other than ReferencesThis issue was introduced by this commit, and is fixed in v0.0.30. Fixed in
0.0.30
References
Updated Mar 19, 2025 · Source: OSV.dev |
0.0.24
unknown
Dependencies (40)
+ 32 more |
|
0.0.23
unknown
|
0.0.23
unknown
Dependencies (40)
+ 32 more |
|
0.0.22
unknown
|
0.0.22
unknown
Dependencies (40)
+ 32 more |
|
0.0.21
unknown
|
0.0.21
unknown
Dependencies (40)
+ 32 more |
|
0.0.20
unknown
|
0.0.20
unknown
Dependencies (40)
+ 32 more |
|
0.0.19
unknown
|
0.0.19
unknown
Dependencies (35)
+ 27 more |
|
0.0.18
unknown
|
0.0.18
unknown
Dependencies (33)
+ 25 more |
|
0.0.17
unknown
|
0.0.17
unknown
Dependencies (32)
+ 24 more |
|
0.0.15
unknown
|
0.0.15
unknown
Dependencies (32)
+ 24 more |
|
0.0.14
unknown
|
0.0.14
unknown
Dependencies (31)
+ 23 more |
|
0.0.13
unknown
|
0.0.13
unknown
Dependencies (29)
+ 21 more |
|
0.0.12
unknown
|
0.0.12
unknown
Dependencies (29)
+ 21 more |
|
0.0.11
unknown
|
0.0.11
unknown
Dependencies (29)
+ 21 more |
|
0.0.10
unknown
|
0.0.10
unknown
Dependencies (27)
+ 19 more |
|
0.0.9
unknown
|
0.0.9
unknown
Dependencies (27)
+ 19 more |
|
0.0.8
unknown
|
0.0.8
unknown
Dependencies (28)
+ 20 more |
|
0.0.7
unknown
|
0.0.7
unknown
Dependencies (28)
+ 20 more |
|
0.0.6
unknown
|
0.0.6
unknown
Dependencies (28)
+ 20 more |
|
0.0.5
unknown
|
0.0.5
unknown
Dependencies (26)
+ 18 more |
|
0.0.4
unknown
|
0.0.4
unknown
Dependencies (25)
+ 17 more |
|
0.0.3
unknown
|
0.0.3
unknown
Dependencies (24)
+ 16 more |
|
0.0.2
unknown
|
0.0.2
unknown
Dependencies (23)
+ 15 more |
|
0.0.1
unknown
|
0.0.1
unknown
Dependencies (19)
+ 11 more |