polkit-0.120-1.fc35.1.x86_64
includes the patch to mitigate the issue (Note that the release part of the package name is 1.fc35.1
, which includes the patch, and not 1.fc35
). You can see it in the Fedora source repo: Tree - rpms/polkit - src.fedoraproject.org
The patch doesn’t change SUID bit. You can examine it here if you know C programming: pkexec: local privilege escalation (CVE-2021-4034) (a2bf5c9c) · Commits · polkit / polkit · GitLab
To actually verify it, there are some PoC (proof of concept) C programs on the internet. You can consult to someone more knowledgeable about C programming and security if you really want to be sure that your systems are not vulnerable and patched.