CVE-2026-41651
CVSS 8.8 HIGH: packageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. EPSS 0.5% (37th percentile).
Vulnerabilities · 123 days ago
A local account on a system with PackageKit enabled can become root without a password. The standard response is to treat this as a package-manager bug, but the real issue is that a central daemon trusted for routine software changes can hand out full administrative control to any local user.
CVE-2026-41651, called Pack2TheRoot, affects PackageKit versions 1.0.2 through 1.3.4 and is fixed in 1.3.5. The report says the flaw has existed for almost 12 years and was confirmed on Ubuntu Desktop and Server, Debian Desktop Trixie 13.4, RockyLinux Desktop 10.1, and Fedora 43 Desktop and Server.
The forward risk is persistence. If a local user can reach root through a package-management daemon, patching closes the bug but does not undo any access already gained, and the same trust model may exist across other distributions that ship PackageKit by default.
CVSS 8.8 HIGH: packageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. EPSS 0.5% (37th percentile).
24 sources covering this story
Meet Fragnesia, the third Linux kernel vulnerability in a month
Called a ‘significant vulnerability,’ it’s similar to Dirty Frag; vendors are scrambling to release patches.
CVE-2026-46300 (Fragnesia): Linux Kernel ESP-in-TCP LPE FAQ | Tenable®
CVE-2026-46300 (Fragnesia) is a Linux kernel privilege escalation in the XFRM ESP-in-TCP subsystem.
Researchers have found and disclosed yet another LPE vulnerability in the Linux kernel: CVE-2026-46300, aka "Fragnesia".
New Linux Kernel Vulnerability Fragnesia Allows Root Privilege Escalation
The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail.
New Fragnesia Flaw Hands Linux Local Users Root Access
New Fragnesia kernel flaw lets unprivileged local users escalate to root on Linux systems
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption
Fragnesia CVE-2026-46300 corrupts Linux page cache via XFRM ESP-in-TCP, enabling local root access on major distros.
New Fragnesia Linux flaw lets attackers gain root privileges
Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to run malicious code as root.
Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP | Wiz Blog
A new page-cache corruption vulnerability in the Dirty Frag family enables unprivileged local attackers to achieve root
Copy.Fail Linux Vulnerability - Schneier on Security
Disclosed by Theori on 29 April 2026 with a working PoC.
One Linux vendor likes the idea, but analysts and users view it as a two-edged sword.
Linux bitten by second severe vulnerability in as many weeks
Production-version patches are coming online and should be installed pronto.
Dirty Frag Exploit Poised to Blow Up on Enterprise Linux Distros
The privilege escalation vulnerability, which is similar to other Linux flaws like Copy Fail and Dirty Pipe, may already be under limited exploitation.
Part of the PlainSec briefing for 2026-05-05