
A original vulnerability dubbed Pack2TheRoot would possibly perchance be exploited within the PackageKit daemon to allow local Linux users to set up or take away system packages and indulge in root permissions.
The flaw is identified as CVE-2026-41651 and obtained a excessive-severity score of 8.8 out of 10. It has continued for nearly 12 years within the PackageKit daemon, a background provider that manages instrument set up, updates, and removal all through Linux methods.
Earlier this week, some files in regards to the vulnerability has been published, alongside with PackageKit version 1.3.5 that addresses the gain 22 situation. On the unreal hand, technical particulars and a demo exploit had been not been disclosed to allow the patches to propagate.
An investigation from the Deutsche Telekom Crimson Workforce uncovered that the explanation for the bug is the mechanism PackageKit uses to handle bundle administration requests.
Namely, the researchers stumbled on that instructions love ‘pkcon set up’ would possibly perchance also make with out requiring authentication below certain stipulations on a Fedora system, allowing them to set up a system bundle.
The usage of the Claude Opus AI tool, they extra explored the aptitude for exploiting this behavior and stumbled on CVE-2026-41651.

Supply: Deutsche Telekom
Impact and fixes
Deutsche Telekom's Crimson Workforce reported their findings to Crimson Hat and PackageKit maintainers on April 8. They state that it’s safe to think that all distributions that stretch with PackageKit pre-build in and enabled out-of-the-field are prone to CVE-2026-41651.
The vulnerability has been present in PackageKit version 1.0.2, released in November 2014, and impacts all variations through 1.3.4, in step with the project's safety advisory.
Researchers' checking out possess confirmed that an attacker would possibly perchance also exploit the the CVE-2026-41651 vulnerability within the next Linux distributions:
- Ubuntu Desktop 18.04 (EOL), 24.04.4 (LTS), 26.04 (LTS beta)
- Ubuntu Server 22.04 – 24.04 (LTS)
- Debian Desktop Trixie 13.4
- RockyLinux Desktop 10.1
- Fedora 43 Desktop
- Fedora 43 Server
The list just is just not exhaustive, though, and any Linux distribution the usage of PackageKit can possess to restful be handled as potentially prone to assaults.
Users can possess to restful upgrade to PackageKit version 1.3.5 as soon as imaginable, and make certain that any assorted instrument the usage of the bundle as a dependency has been moved to a safe birth.
Users can utilize the instructions below to test within the event that they've a susceptible version of the PackageKit build in and if the daemon is running:
dpkg -l | grep -i packagekit
rpm -qa | grep -i packagekit
Users can poke systemctl status packagekit or pkmon to test if the PackageKit daemon is accessible and running, which indicates that the system will likely be at threat if left unpatched.
Though no particulars in regards to the state of exploitation had been shared, the researchers notorious that there are stable signs exhibiting compromise because exploitation results within the PackageKit daemon hitting an assertion failure and crashing.
Even though systemd recovers the daemon, the crash is observable within the system logs.
OSINT ninety 9% of What Mythos Came all through Is Calm Unpatched.
AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of original exploits is coming.
At the Self sustaining Validation Summit (Might maybe moreover 12 & 14), leer how self sustaining, context-rich validation finds what's exploitable, proves controls withhold, and closes the remediation loop.
Learn More

