Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:19141

Опубликовано: 29 мая 2026
Источник: rocky
Оценка: Important

Описание

Important: PackageKit security update

PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.

Security Fix(es):

  • PackageKit: race condition vulnerability leads to arbitrary package installation as root (CVE-2026-41651)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
PackageKit-gstreamer-pluginaarch648.el10PackageKit-gstreamer-plugin-1.2.8-8.el10.aarch64.rpm
PackageKit-glibaarch648.el10PackageKit-glib-1.2.8-8.el10.aarch64.rpm
PackageKit-gtk3-moduleaarch648.el10PackageKit-gtk3-module-1.2.8-8.el10.aarch64.rpm
PackageKitaarch648.el10PackageKit-1.2.8-8.el10.aarch64.rpm
PackageKit-command-not-foundaarch648.el10PackageKit-command-not-found-1.2.8-8.el10.aarch64.rpm
PackageKit-glibx86_648.el10PackageKit-glib-1.2.8-8.el10.x86_64.rpm
PackageKit-command-not-foundx86_648.el10PackageKit-command-not-found-1.2.8-8.el10.x86_64.rpm
PackageKit-gstreamer-pluginx86_648.el10PackageKit-gstreamer-plugin-1.2.8-8.el10.x86_64.rpm
PackageKit-gtk3-modulex86_648.el10PackageKit-gtk3-module-1.2.8-8.el10.x86_64.rpm
PackageKitx86_648.el10PackageKit-1.2.8-8.el10.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 месяца назад

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction ...

CVSS3: 8.8
redhat
3 месяца назад

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction ...

CVSS3: 8.8
nvd
3 месяца назад

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction ha

CVSS3: 8.8
debian
3 месяца назад

PackageKit is a a D-Bus abstraction layer that allows the user to mana ...

suse-cvrf
3 месяца назад

Security update for PackageKit