CVE-2026-41651
published 2026-04-22CVE-2026-41651: PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit…
PriorityP354high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.46%
37.6th percentile
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.
A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`:
1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING.
2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags.
3. Late flag read at execution time (lines 2273–2277): The scheduler's idle callback reads cached_transaction_flags at dispatch time, not at authorization time. If flags were overwritten between authorization and execution, the backend sees the attacker's flags.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| packagekit | packagekit | — | — |
| packagekit | packagekit | — | — |
| packagekit_project | packagekit | >= 1.0.2 < 1.3.5 | 1.3.5 |
| ubuntu | packagekit | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PackageKit vulnerability
vendor_ubuntu·2026-04-29
CVE-2026-41651 PackageKit vulnerability
Title: PackageKit vulnerability
Summary: PackageKit could be made to install packages as the administrator.
USN-8195-1 fixed a vulnerability in PackageKit. This update provides
the corresponding fix to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that PackageKit incorrectly handled certain transactions.
A local attacker could use this issue to install arbitrary packages as
root, possibly resulting in privilege escalation.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
PackageKit: race condition vulnerability leads to arbitrary package installation as root
vendor_redhat·2026-04-22·CVSS 8.8
CVE-2026-41651 [HIGH] CWE-367 PackageKit: race condition vulnerability leads to arbitrary package installation as root
PackageKit: race condition vulnerability leads to arbitrary package installation as root
A flaw was found in PackageKit. A time-of-check time-of-use (TOCTOU) race condition on transaction flags allows unprivileged users to install packages as root, resulting in a local privilege escalation.
Statement: To exploit this issue, an attacker needs local access to the system and basic permissions to install packages via PackageKit, limiting its exposure to authenticated users. As this flaw allows a local user to escalate its privileges, specifically gaining administrative permissions, this vulnerability has been rated with an important severity.
Mitigation: To mitigate this vulnerability, mask the PackageKit service. Note that graphical package managers, such as GNOME software, will not work a
VulDB
PackageKit up to 1.3.4 src/pk-transaction.c InstallFiles toctou (WID-SEC-2026-1233)
vuldb·2026-04-23·CVSS 8.8
CVE-2026-41651 [HIGH] PackageKit up to 1.3.4 src/pk-transaction.c InstallFiles toctou (WID-SEC-2026-1233)
A vulnerability has been found in PackageKit up to 1.3.4 and classified as problematic. This impacts the function InstallFiles of the file src/pk-transaction.c. Performing a manipulation results in time-of-check time-of-use.
This vulnerability is identified as CVE-2026-41651. The attack is only possible with local access. There is not any exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
Hackernews
DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
blogs_hackernews·2026-05-19·CVSS 7.5
CVE-2026-31635 [HIGH] DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE).
Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 2026, only to be informed by the maintainers that it was a duplicate of a vulnerability that had already been patched in the mainline.
"It's a rxgk pagecache write due to missing COW [copy-on-write] guard in rxgk_decrypt_skb," Zellic co-founder Luna Tong (a
Bleepingcomputer
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
blogs_bleepingcomputer·2026-05-04·CVSS 7.8
CVE-2026-31431 [HIGH] CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
## CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
## Sergiu Gatlan
On Friday, CISA added the Copy Fail security flaw to its Known Exploited Vulnerabilities (KEV) Catalog , ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Linux endpoints and servers within two weeks, by May 15, as mandated by Binding Operational Directive (BOD) 22-01 .
"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the U.S. cybersecurity agency warned.
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."
While BOD 22-01 applies only to U.S. government agencies, CISA urged all
Hackernews
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
blogs_hackernews·2026-04-27
CVE-2025-20333 ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are.
Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen creds. Remote tools are getting abused. Malware hides in places people trust. Same mess, cleaner packaging.
Coffee is cold. The vuln list is ugly. Let’s get into it.
## ⚡ Threat of the Week
New fast16 Malware Was Developed Y
Bleepingcomputer
New ‘Pack2TheRoot’ flaw gives hackers root Linux access
blogs_bleepingcomputer·2026-04-24·CVSS 8.8
CVE-2026-41651 [HIGH] New ‘Pack2TheRoot’ flaw gives hackers root Linux access
## New ‘Pack2TheRoot’ flaw gives hackers root Linux access
## Bill Toulas
An investigation from the Deutsche Telekom Red Team uncovered that the cause of the bug is the mechanism PackageKit uses to handle package management requests.
Specifically, the researchers found that commands like ‘pkcon install’ could execute without requiring authentication under certain conditions on a Fedora system, allowing them to install a system package.
Using the Claude Opus AI tool, they further explored the potential for exploiting this behavior and discovered CVE-2026-41651.
## Impact and fixes
Deutsche Telekom's Red Team reported their findings to Red Hat and PackageKit maintainers on April 8. They state that it’s safe to assume that all distributions that come with PackageKit pre-installed and en
Bugzilla
CVE-2026-41651 PackageKit: race condition vulnerability leads to arbitrary package installation as root [fedora-all]
bugzilla·2026-04-22·CVSS 8.8
CVE-2026-41651 [HIGH] CVE-2026-41651 PackageKit: race condition vulnerability leads to arbitrary package installation as root [fedora-all]
CVE-2026-41651 PackageKit: race condition vulnerability leads to arbitrary package installation as root [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
*** This bug has been marked as a duplicate of bug 2460579 ***
Bugzilla
CVE-2026-41651 PackageKit: race condition vulnerability leads to arbitrary package installation as root
bugzilla·2026-04-22·CVSS 8.8
CVE-2026-41651 [HIGH] CVE-2026-41651 PackageKit: race condition vulnerability leads to arbitrary package installation as root
CVE-2026-41651 PackageKit: race condition vulnerability leads to arbitrary package installation as root
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.
A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard
https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L2273-L2277https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L4036https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L873-L882https://github.com/PackageKit/PackageKit/security/advisories/GHSA-f55j-vvr9-69xvhttps://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.htmlhttp://www.openwall.com/lists/oss-security/2026/04/22/6https://access.redhat.com/errata/RHSA-2026:11504https://access.redhat.com/errata/RHSA-2026:11635https://access.redhat.com/errata/RHSA-2026:17558https://access.redhat.com/errata/RHSA-2026:17560https://access.redhat.com/errata/RHSA-2026:17561https://access.redhat.com/errata/RHSA-2026:18024https://access.redhat.com/errata/RHSA-2026:18031https://access.redhat.com/errata/RHSA-2026:18036https://access.redhat.com/errata/RHSA-2026:19141https://access.redhat.com/errata/RHSA-2026:19354https://access.redhat.com/errata/RHSA-2026:19454https://access.redhat.com/errata/RHSA-2026:19601https://access.redhat.com/errata/RHSA-2026:22146https://access.redhat.com/security/cve/CVE-2026-41651https://bugzilla.redhat.com/show_bug.cgi?id=2460604https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41651.json
2026-04-22
Published