Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System
ID: cade93fe-2eb2-52d7-89b3-e7861a139e58
STIX ID: report--cade93fe-2eb2-52d7-89b3-e7861a139e58
Feed Name: cybersecurityNews.com
**Pack2TheRoot (CVE-2026-41651)** is a high-severity (CVSS 3.1: 8.8) local privilege escalation in PackageKit (affecting versions 1.0.2–1.3.4) present in default installations of many major Linux distributions (Ubuntu, Debian, Fedora, Rocky, RHEL/Cockpit), allowing unprivileged local users to silently install/remove system packages and gain root; a reliable PoC achieves root in seconds, exploitation triggers an assertion at pk-transaction.c:514 and log entries detectable via journalctl, and the issue is fixed in PackageKit 1.3.5 (released 2026-04-22) with distribution-specific patches available—administrators should apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
