CVE-2026-41651
CVSS 8.8 HIGH: packageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. EPSS 0.5% (37th percentile).
Vulnerabilities & Exploits
A local account on a system with PackageKit enabled can become root without a password. The standard response is to treat this as a package-manager bug, but the real issue is that a central daemon trusted for routine software changes can hand out full administrative control to any local user.
CVE-2026-41651, called Pack2TheRoot, affects PackageKit versions 1.0.2 through 1.3.4 and is fixed in 1.3.5. The report says the flaw has existed for almost 12 years and was confirmed on Ubuntu Desktop and Server, Debian Desktop Trixie 13.4, RockyLinux Desktop 10.1, and Fedora 43 Desktop and Server.
The forward risk is persistence. If a local user can reach root through a package-management daemon, patching closes the bug but does not undo any access already gained, and the same trust model may exist across other distributions that ship PackageKit by default.
24 sources · May 15
CVSS 8.8 HIGH: packageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. EPSS 0.5% (37th percentile).
CSO Online
Meet Fragnesia, the third Linux kernel vulnerability in a month
Called a ‘significant vulnerability,’ it’s similar to Dirty Frag; vendors are scrambling to release patches.
originalTenable
CVE-2026-46300 (Fragnesia): Linux Kernel ESP-in-TCP LPE FAQ | Tenable®
CVE-2026-46300 (Fragnesia) is a Linux kernel privilege escalation in the XFRM ESP-in-TCP subsystem.
originalHelp Net Security
Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) - Help Net Security
Researchers have found and disclosed yet another LPE vulnerability in the Linux kernel: CVE-2026-46300, aka "Fragnesia".
originalPart of the PlainSec briefing for 2026-04-28
Every edition of this story: PackageKit Auth Bypass Turns Local Users Root