CVE-2026-41651
PackageKit PackageKit, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race...
- CVSS
- 8.8
- EPSS
- 0.46% 37.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.22