logo

Pardus Linux Vulnerability Lets Local Attackers Gain Silent Root Access

ID: c7635ff4-5919-5a75-8bd4-e4c4ed4a0237

STIX ID: report--c7635ff4-5919-5a75-8bd4-e4c4ed4a0237

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Divya

...
...

**Executive Summary:** A critical CVE-2026-5140 privilege escalation chain in Pardus Linux's pardus-update utility allows local unprivileged users to obtain full root access by chaining a Polkit authorization bypass, CRLF injection into configuration, and copying attacker-controlled APT sources; the report includes a working proof-of-concept using pkexec and recommends hardening Polkit policies, proper input sanitization, and validation of APT repository paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.