logo

Pack2TheRoot: 12-Year-Old Linux PackageKit Flaw Enables Full Compromise

ID: d7b119e3-d9f4-5586-b911-1197d0989e5e

STIX ID: report--d7b119e3-d9f4-5586-b911-1197d0989e5e

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Deeba Ahmed

...
...

Researchers disclosed Pack2TheRoot (CVE-2026-41651), a high-severity TOCTOU race condition in PackageKit that enables unprivileged local users to install arbitrary RPMs and run scriptlets to gain root; it affects many distributions (PackageKit 1.0.2–1.3.4), has CVSS 8.8, a public PoC, and was patched in PackageKit 1.3.5 on 22 April 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.