Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19816

Опубликовано: 09 сент. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.

A flaw was found in PackageKit. In the dnf5 backend, the RepoRemove handler ignores the SIMULATE transaction flag and executes a real package removal, allowing an unprivileged local user to uninstall packages without polkit authorization.

Отчет

This issue affects Fedora systems using PackageKit with the dnf5 backend. Red Hat Enterprise Linux is not affected because it ships PackageKit 1.2.x with the classic dnf backend, which does not include the vulnerable dnf5 code path. An attacker requires local access and the ability to invoke PackageKit as an unprivileged user. This flaw allows unauthorized package removal and can affect system integrity and availability, but does not provide arbitrary package installation or a root shell.

Меры по смягчению последствий

Affects v1.3.4 through v1.3.6. Fixed in commit 33be77b. Upgrade to v1.4.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10PackageKitNot affected
Red Hat Enterprise Linux 6PackageKitNot affected
Red Hat Enterprise Linux 7compat-PackageKit08Not affected
Red Hat Enterprise Linux 7PackageKitNot affected
Red Hat Enterprise Linux 8PackageKitNot affected
Red Hat Enterprise Linux 9PackageKitNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2515940packagekit: PackageKit: PackageKit dnf5 ignores SIMULATE on RepoRemove

EPSS

Процентиль: 4%
0.00143
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
6 дней назад

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.

CVSS3: 7.1
nvd
6 дней назад

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.

CVSS3: 7.1
debian
6 дней назад

A flaw was found in PackageKit. PackageKit skips the polkit authorizat ...

CVSS3: 7.1
fstec
7 дней назад

Уязвимость функции RepoRemove() пакетного менеджера PackageKit, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

EPSS

Процентиль: 4%
0.00143
Низкий

7.1 High

CVSS3