logo

Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System

ID: cade93fe-2eb2-52d7-89b3-e7861a139e58

STIX ID: report--cade93fe-2eb2-52d7-89b3-e7861a139e58

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Guru Baran

...
...

**Pack2TheRoot (CVE-2026-41651)** is a high-severity (CVSS 3.1: 8.8) local privilege escalation in PackageKit (affecting versions 1.0.2–1.3.4) present in default installations of many major Linux distributions (Ubuntu, Debian, Fedora, Rocky, RHEL/Cockpit), allowing unprivileged local users to silently install/remove system packages and gain root; a reliable PoC achieves root in seconds, exploitation triggers an assertion at pk-transaction.c:514 and log entries detectable via journalctl, and the issue is fixed in PackageKit 1.3.5 (released 2026-04-22) with distribution-specific patches available—administrators should apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.