logo

12-year-old Pack2TheRoot bug lets Linux users gain root privileges

ID: a0ee9b03-9de4-5131-9cce-d11a6ad8673c

STIX ID: report--a0ee9b03-9de4-5131-9cce-d11a6ad8673c

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Pierluigi Paganini

...
...

Deutsche Telekom Red Team disclosed a long-lived high-severity PackageKit vulnerability (CVE-2026-41651, "Pack2TheRoot") present in PackageKit versions 1.0.2–1.3.4 that can allow a local unprivileged user to install packages without authentication and obtain root; fixes were released in PackageKit 1.3.5 and distributions have issued patches, while researchers withheld public exploit code and provided IOCs to mitigate abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.