[Pkg-utopia-maintainers] Bug#1093276: polkit: When entering (correct) password, then waiting for timeout, password gets copied on CLI!

li ar liar666 at yopmail.com
Fri Jan 17 10:23:27 GMT 2025


Package: polkitd
Version: 122-3
Severity: important
File: polkit
X-Debbugs-Cc: liar666 at yopmail.com

Dear Maintainer,

*** Reporter, please consider answering these questions, where appropriate ***

Hello,

I'm using LMDE6 (Linux Mint based on Debian 12).

When, as a normal user, I call a command that requires root privileges on the command line, instead of getting rejected, I'm asked for root/sudo password. I think the tool used to do that is polkit. That's why I post here.

When I enter my (correct) password, but then DO NOT validate it by hitting return, then let the login/sudo TIMEOUT trigger, then my actual password get copy-pasted on the command line!!!!

When I use "sudo" directly, there is no timeout, thus it does not happen.

Example:
```
[✘] user at localmachine:~$ service ollama stop
==== AUTHENTICATING FOR org.freedesktop.systemd1.manage-units ====  ## <- I think it is polkit/pkexec that's called here?
Authentication is required to stop 'ollama.service'.
Authenticating as: USER,,, (user)
Password: Failed to stop ollama.service: Connection timed out       ## <- I just wait for timeout here
See system logs and 'systemctl status ollama.service' for details.
polkit-agent-helper-1: pam_authenticate failed: Authentication failure
[✘] user at localmachine:~$ MyPassw0rd!                                ## My password is pasted on the CLI!!!!
```


*** End of the template - remove these template lines ***


-- System Information:
Debian Release: 12.1
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.1.0-28-amd64 (SMP w/16 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages policykit-1 depends on:
ii  pkexec   122-3
ii  polkitd  122-3

Versions of packages policykit-1 recommends:
pn  polkitd-pkla  <none>

policykit-1 suggests no packages.

Versions of packages polkitd depends on:
ii  adduser                         3.134+mint1
ii  dbus [default-dbus-system-bus]  1.14.10-1~deb12u1
ii  libc6                           2.36-9+deb12u9
ii  libduktape207                   2.7.0-2
ii  libexpat1                       2.5.0-1+deb12u1
ii  libglib2.0-0                    2.74.6-2+deb12u4
ii  libpam-systemd [logind]         252.31-1~deb12u1
ii  libpam0g                        1.5.2-6+deb12u1
ii  libpolkit-agent-1-0             122-3
ii  libpolkit-gobject-1-0           122-3
ii  libsystemd0                     252.31-1~deb12u1
ii  systemd [systemd-sysusers]      252.31-1~deb12u1
ii  xml-core                        0.18+nmu1

Versions of packages polkitd suggests:
pn  polkitd-pkla  <none>

-- no debconf information


More information about the Pkg-utopia-maintainers mailing list