A vulnerability in PackageKit allows obtaining root privileges in various Linux distributions
A vulnerability, Pack2TheRoot (CVE-2026-41651), has been identified in PackageKit, a D-Bus layer that unifies package management operations, allowing an unprivileged user to install or remove arbitrary packages and gain root access to the system. The issue manifests starting with version 1.0.2 (2014) and has been addressed in the PackageKit 1.3.5 release. The problem was discovered by researchers from Deutsche Telekom using the AI model Claude Opus. A functional exploit has been prepared that operates in […]
