{"id":169876,"date":"2026-04-24T12:24:33","date_gmt":"2026-04-24T10:24:33","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-packagekit-pozvolyayushhaya-poluchit-prava-root-v-raznyh-distributivah-linux"},"modified":"2026-04-24T12:24:33","modified_gmt":"2026-04-24T10:24:33","slug":"uyazvimost-v-packagekit-pozvolyayushhaya-poluchit-prava-root-v-raznyh-distributivah-linux","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-packagekit-pozvolyayushhaya-poluchit-prava-root-v-raznyh-distributivah-linux","title":{"rendered":"O vulnerabilitate \u00een PackageKit, care permite ob\u021binerea drepturilor root \u00een diferite distribu\u021bii Linux.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cen PackageKit, straturile D-Bus care unific\u0103 opera\u021biunile de gestionare a pachetelor, a fost descoperit\u0103 vulnerabilitatea Pack2TheRoot (CVE-2026-41651), care permite unui utilizator neprivilegiat s\u0103 instaleze sau s\u0103 elimine un pachet arbitrar \u0219i s\u0103 ob\u021bin\u0103 acces root la sistem. Problema se manifest\u0103 \u00eencep\u00e2nd cu versiunea 1.0.2 (anul 2014) \u0219i a fost rezolvat\u0103 \u00een versiunea PackageKit 1.3.5.    <\/p>\n<p>Problema a fost identificat\u0103 de cercet\u0103torii companiei Deutsche Telekom cu ajutorul modelului AI Claude Opus. A fost preg\u0103tit un exploit func\u021bional, care ac\u021bioneaz\u0103 \u00een majoritatea distribu\u021biilor cu PackageKit, dar acesta \u0219i informa\u021biile detaliate despre vulnerabilitate urmeaz\u0103 s\u0103 fie publicate ulterior, pentru a oferi utilizatorilor timp s\u0103-\u0219i actualizeze sistemele. Posibilitatea exploat\u0103rii vulnerabilit\u0103\u021bii a fost demonstrat\u0103 \u00een Ubuntu Desktop 18.04\/24.04.4\/26.04, Ubuntu Server 22.04 \u2014 24.04, Debian Desktop 13.4, RockyLinux Desktop 10.1 \u0219i Fedora 43 Desktop\/Server. Statutul remedierii vulnerabilit\u0103\u021bilor \u00een distribu\u021bii poate fi evaluat pe aceste pagini (dac\u0103 pagina este indisponibil\u0103, \u00eenseamn\u0103 c\u0103 dezvoltatorii distribu\u021biei nu au \u00eenceput \u00eenc\u0103 s\u0103 analizeze problema): Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch, Fedora, FreeBSD.      <\/p>\n<p>Vulnerabilitatea este cauzat\u0103 de o competi\u021bie \u00eentre fire la procesarea flagurilor de tranzac\u021bie \u00een procesul de fundal PackageKit, care permite modificarea parametrilor opera\u021biei \u00eentre trecerea prin autorizare \u0219i \u00eenceputul efectiv al opera\u021biei cu pachetul. Atacatorul poate trimite o solicitare D-Bus pentru a efectua o opera\u021bie permis\u0103 pentru un utilizator neprivilegiat, dup\u0103 care poate trimite o a doua solicitare D-Bus. Dac\u0103 a doua solicitare ajunge \u00eenainte de \u00eenceputul efectiv al opera\u021biei permise, parametrii tranzac\u021biei deja \u00eencepute pot fi redefini\u021bi, alter\u00e2nd astfel starea cache-ului.     <\/p>\n<p>Astfel, o tranzac\u021bie deja \u00eenceput\u0103 \u0219i permis\u0103 va fi executat\u0103 cu parametrii modifica\u021bi \u0219i nu cu cei originali, ci cu parametrii substitui\u021bi transmi\u0219i \u00een a doua solicitare. Prin modificarea informa\u021biilor despre pachetul ce urmeaz\u0103 a fi instalat, se poate \u00eenlocui pachetul permis cu orice alt pachet, inclusiv unul salvat local de atacator. Instalarea pachetului se face cu drepturi root, iar pentru a ob\u021bine acces root \u00een sistem, atacatorul poate ad\u0103uga un script personalizat \u00een pachet, care va fi lansat automat \u00eenainte sau dup\u0103 instalare.          <center><img decoding=\"async\" alt=\"O vulnerabilitate \u00een PackageKit, care permite ob\u021binerea drepturilor root \u00een diferite distribu\u021bii Linux. \" src=\"\/wp-content\/uploads\/2026\/04\/097148fb0ba4207d4c0ce32a5c4d0ee9.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65277\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 PackageKit, D-Bus-\u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0435, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0439 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u0430\u043c\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c Pack2TheRoot (CVE-2026-41651), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438\u043b\u0438 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043f\u0430\u043a\u0435\u0442 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c root-\u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u0441 \u0432\u0435\u0440\u0441\u0438\u0438 1.0.2 (2014 \u0433\u043e\u0434) \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 PackageKit 1.3.5. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Deutsche Telekom \u043f\u0440 \u043f\u043e\u043c\u043e\u0449\u0438 AI-\u043c\u043e\u0434\u0435\u043b\u0438 Claude Opus. \u041f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u0440\u0430\u0431\u043e\u0447\u0438\u0439 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442, \u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0439 \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":169877,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-169876","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 PackageKit, D-Bus-\u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0435, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0439 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u0430\u043c\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c Pack2TheRoot (CVE-2026-41651), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438\u043b\u0438 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043f\u0430\u043a\u0435\u0442 \u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-packagekit-pozvolyayushhaya-poluchit-prava-root-v-raznyh-distributivah-linux\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 PackageKit, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0440\u0430\u0437\u043d\u044b\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 PackageKit, D-Bus-\u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0435, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0439 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u0430\u043c\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c Pack2TheRoot (CVE-2026-41651), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438\u043b\u0438 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043f\u0430\u043a\u0435\u0442 \u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-packagekit-pozvolyayushhaya-poluchit-prava-root-v-raznyh-distributivah-linux\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-04-24T10:24:33+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-04-24T10:24:33+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een PackageKit, care permite ob\u021binerea de drepturi root \u00een diverse distribu\u021bii Linux | ProHoster","description":"\u00cen PackageKit, interfa\u021ba D-Bus care unific\u0103 opera\u021biunile de gestionare a pachetelor, a fost descoperit\u0103 o vulnerabilitate Pack2TheRoot (CVE-2026-41651), care permite unui utilizator nemijlocit s\u0103 instaleze sau s\u0103 elimine un pachet arbitrar.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-packagekit-pozvolyayushhaya-poluchit-prava-root-v-raznyh-distributivah-linux","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 PackageKit, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0440\u0430\u0437\u043d\u044b\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430\u0445 Linux | ProHoster","og:description":"\u0412 PackageKit, D-Bus-\u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0435, \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0435\u0439 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0438 \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u0430\u043c\u0438, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c Pack2TheRoot (CVE-2026-41651), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c \u0438\u043b\u0438 \u0443\u0434\u0430\u043b\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043f\u0430\u043a\u0435\u0442 \u0438.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-packagekit-pozvolyayushhaya-poluchit-prava-root-v-raznyh-distributivah-linux","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-04-24T10:24:33+00:00","article:modified_time":"2026-04-24T10:24:33+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/169876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=169876"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/169876\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/169877"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=169876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=169876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=169876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}