Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Fedora 43 PackageKit Critical Root Compromise Threat 2026-7463cd3c32

fedora
Calendar Grey April 28, 2026
Dist Fedora Esm H88
Fixed root compromise risk in PackageKit for Fedora 43. Ensure system security with this critical update.
Backport fix for race condition leading to root compromise (GHSA-f55j-vvr9-69xv)

Summary

PackageKit is a D-Bus abstraction layer that allows the session user

to manage packages in a secure way using a cross-distro,

cross-architecture API.

Update Information:

Backport fix for race condition leading to root compromise (GHSA-f55j-vvr9-69xv)

Change Log

* Wed Apr 22 2026 Neal Gompa - 1.3.4-3 - Actually apply patch for security fix * Wed Apr 22 2026 Neal Gompa - 1.3.4-2 - Backport fix for GHSA-f55j-vvr9-69xv

References


[ 1 ] Bug #2460579 - Local Privilege escalation: Run code as root due to race condition in PackageKit https://bugzilla.redhat.com/show_bug.cgi?id=2460579

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7463cd3c32' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: PackageKit
Product: Fedora 43
Version: 1.3.4
Release: 3.fc43
Summary: Package management service

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here