logo

New ‘Pack2TheRoot’ flaw gives hackers root Linux access

ID: 31c2dbf7-9180-5a57-8afe-de4d9611f7cd

STIX ID: report--31c2dbf7-9180-5a57-8afe-de4d9611f7cd

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Bill Toulas

...
...

A newly disclosed PackageKit vulnerability dubbed Pack2TheRoot (CVE-2026-41651) permits local Linux users to install or remove system packages and obtain root privileges; it affects PackageKit versions 1.0.2 through 1.3.4 (present since 2014) across multiple distributions and is fixed in PackageKit 1.3.5 — administrators are advised to verify PackageKit versions and update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.