Описание
Security update for PackageKit
This update for PackageKit fixes the following issues:
Security issue fixed:
- CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250).
Non security issue fixed:
- KDE Discover ignores package locks (bsc#1263252).
Список пакетов
openSUSE Leap 16.0
PackageKit-1.2.8-160000.5.1
PackageKit-backend-dnf-1.2.8-160000.5.1
PackageKit-backend-zypp-1.2.8-160000.5.1
PackageKit-branding-upstream-1.2.8-160000.5.1
PackageKit-devel-1.2.8-160000.5.1
PackageKit-gstreamer-plugin-1.2.8-160000.5.1
PackageKit-gtk3-module-1.2.8-160000.5.1
PackageKit-lang-1.2.8-160000.5.1
libpackagekit-glib2-18-1.2.8-160000.5.1
libpackagekit-glib2-devel-1.2.8-160000.5.1
typelib-1_0-PackageKitGlib-1_0-1.2.8-160000.5.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1263252
- SUSE Bug 1267250
- SUSE CVE CVE-2026-10294 page
Описание
A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Затронутые продукты
openSUSE Leap 16.0:PackageKit-1.2.8-160000.5.1
openSUSE Leap 16.0:PackageKit-backend-dnf-1.2.8-160000.5.1
openSUSE Leap 16.0:PackageKit-backend-zypp-1.2.8-160000.5.1
openSUSE Leap 16.0:PackageKit-branding-upstream-1.2.8-160000.5.1
Ссылки
- CVE-2026-10294
- SUSE Bug 1267250