← Vulnerability feed

Vulnerability record · CVE-2026-41651 · published 22 April 2026

CVE-2026-41651: Packagekit project packagekit toctou race condition vulnerability

Packagekit Project · Packagekit

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING. 2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags. 3. Late flag read at execution time (lines 2273–2277): The scheduler's idle callback reads cached_transaction_flags at dispatch time, not at authorization time. If flags were overwritten between authorization and execution, the backend sees the attacker's flags.

8.8 CVSS 3.1 High EPSS 0.19% · top 92.1% CWE-367 · TOCTOU race condition
8.8CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References, 2 tagged exploit
15 Jul 2026Last modified by NVD

Description

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING. 2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags. 3. Late flag read at execution time (lines 2273–2277): The scheduler's idle callback reads cached_transaction_flags at dispatch time, not at authorization time. If flags were overwritten between authorization and execution, the backend sees the attacker's flags.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L2273-L2277 Product
https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L4036 Product
https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L873-L882 Product
https://github.com/PackageKit/PackageKit/security/advisories/GHSA-f55j-vvr9-69xv ExploitVendor Advisory
https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html ExploitThird Party Advisory
http://www.openwall.com/lists/oss-security/2026/04/22/6 Mailing ListPatchThird Party Advisory
https://access.redhat.com/errata/RHSA-2026:11504
https://access.redhat.com/errata/RHSA-2026:11635
https://access.redhat.com/errata/RHSA-2026:17558
https://access.redhat.com/errata/RHSA-2026:17560
https://access.redhat.com/errata/RHSA-2026:17561
https://access.redhat.com/errata/RHSA-2026:18024
https://access.redhat.com/errata/RHSA-2026:18031
https://access.redhat.com/errata/RHSA-2026:18036
https://access.redhat.com/errata/RHSA-2026:19141
https://access.redhat.com/errata/RHSA-2026:19354
https://access.redhat.com/errata/RHSA-2026:19454
https://access.redhat.com/errata/RHSA-2026:19601
https://access.redhat.com/errata/RHSA-2026:22146
https://access.redhat.com/security/cve/CVE-2026-41651
https://bugzilla.redhat.com/show_bug.cgi?id=2460604
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41651.json

Track CVE-2026-41651 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-16122Packagekit project packagekit improper privilege management vulnerabilityPackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of…EPSS 0.34%5.5CVE-2018-1106Packagekit project packagekit improper authentication vulnerabilityAn authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package…EPSS 0.39%5.3CVE-2011-2515Packagekit project packagekit incorrect permission assignment vulnerabilityPackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and ex…EPSS 0.39%3.3CVE-2024-0217Packagekit project packagekit use after free vulnerabilityA use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, …EPSS 0.23%3.3CVE-2022-0987Packagekit project packagekit information exposure vulnerabilityA flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to …EPSS 0.26%3.3CVE-2020-16121Packagekit project packagekit error message information leak vulnerabilityPackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user …EPSS 0.47%2.1CVE-2013-1764Packagekit project packagekit permissions and access controls vulnerabilityThe Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.EPSS 0.38%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed

Source: NIST National Vulnerability Database (record CVE-2026-41651), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.