logo

Linux Privilege Escalation: “Pack2TheRoot” Flaw Impacts Major Distributions

ID: 8bec7857-cf0f-5ca7-8817-02dd41b3dc41

STIX ID: report--8bec7857-cf0f-5ca7-8817-02dd41b3dc41

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

Pack2TheRoot (CVE-2026-41651) is a high-severity race-condition vulnerability in PackageKit (versions 1.0.2–1.3.4) that enables local, unprivileged attackers to escalate to root by exploiting a timing window in the package installation process. Discovered by Deutsche Telekom’s Red Team and tested against apt and dnf backends, the flaw affects multiple major Linux distributions (including several Ubuntu, Debian, RockyLinux, and Fedora releases); maintainers released a patch in PackageKit >=1.3.5 and administrators are urged to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.