top of page
perceptive_background_267k.jpg

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit betwe…

Published:

21 april 2026 om 22:00:00

Alert date:

22 april 2026 om 22:11:22

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Supply Chain & Dependencies

PackageKit versions 1.0.2 through 1.3.4 contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that allows unprivileged local users to install arbitrary RPM packages as root, leading to privilege escalation. The vulnerability involves three bugs in transaction flag handling that allow attackers to overwrite cached transaction flags during execution. The flaw enables installation of packages and execution of RPM scriptlets without authentication. This critical vulnerability has been patched in version 1.3.5.

Technical details

Mitigation steps:

Affected products:

PackageKit

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page