Описание
A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
A flaw was found in PackageKit. In the dnf5 backend, the RepoRemove handler ignores the SIMULATE transaction flag and executes a real package removal, allowing an unprivileged local user to uninstall packages without polkit authorization.
Отчет
This issue affects Fedora systems using PackageKit with the dnf5 backend. Red Hat Enterprise Linux is not affected because it ships PackageKit 1.2.x with the classic dnf backend, which does not include the vulnerable dnf5 code path. An attacker requires local access and the ability to invoke PackageKit as an unprivileged user. This flaw allows unauthorized package removal and can affect system integrity and availability, but does not provide arbitrary package installation or a root shell.
Меры по смягчению последствий
Affects v1.3.4 through v1.3.6. Fixed in commit 33be77b. Upgrade to v1.4.0.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | PackageKit | Not affected | ||
| Red Hat Enterprise Linux 6 | PackageKit | Not affected | ||
| Red Hat Enterprise Linux 7 | compat-PackageKit08 | Not affected | ||
| Red Hat Enterprise Linux 7 | PackageKit | Not affected | ||
| Red Hat Enterprise Linux 8 | PackageKit | Not affected | ||
| Red Hat Enterprise Linux 9 | PackageKit | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
A flaw was found in PackageKit. PackageKit skips the polkit authorizat ...
Уязвимость функции RepoRemove() пакетного менеджера PackageKit, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации
EPSS
7.1 High
CVSS3