CVE-2026-41651
CVSS 8.8 HIGH: packageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. EPSS 0.2% (8º percentile).
Vulnerabilità ed exploit
A local account on a system with PackageKit enabled can become root without a password. The standard response is to treat this as a package-manager bug, but the real issue is that a central daemon trusted for routine software changes can hand out full administrative control to any local user.
CVE-2026-41651, called Pack2TheRoot, affects PackageKit versions 1.0.2 through 1.3.4 and is fixed in 1.3.5. The report says the flaw has existed for almost 12 years and was confirmed on Ubuntu Desktop and Server, Debian Desktop Trixie 13.4, RockyLinux Desktop 10.1, and Fedora 43 Desktop and Server.
The forward risk is persistence. If a local user can reach root through a package-management daemon, patching closes the bug but does not undo any access already gained, and the same trust model may exist across other distributions that ship PackageKit by default.
24 fonti · 15 mag
CVSS 8.8 HIGH: packageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. EPSS 0.2% (8º percentile).
CSO Online
Meet Fragnesia, the third Linux kernel vulnerability in a month
Called a ‘significant vulnerability,’ it’s similar to Dirty Frag; vendors are scrambling to release patches.
originaleTenable
CVE-2026-46300 (Fragnesia): Linux Kernel ESP-in-TCP LPE FAQ | Tenable®
CVE-2026-46300 (Fragnesia) is a Linux kernel privilege escalation in the XFRM ESP-in-TCP subsystem.
originaleHelp Net Security
Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) - Help Net Security
Researchers have found and disclosed yet another LPE vulnerability in the Linux kernel: CVE-2026-46300, aka "Fragnesia".
originalePart of the PlainSec briefing for 2026-05-03
Every edition of this story: PackageKit Auth Bypass Turns Local Users Root