Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Warning: Undefined array key "Description" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 220

Fedora 42 PackageKit Vulnerability Causes Local Privilege Escalation Risk

fedora
Calendar Grey April 28, 2026
Dist Fedora Esm H88
Fix for race condition in Fedora PackageKit allows root exploitation. Immediate action recommended for security as severity is critical.
Backport fix for race condition leading to root compromise (GHSA-f55j-vvr9-69xv)

Summary

PackageKit is a D-Bus abstraction layer that allows the session user

to manage packages in a secure way using a cross-distro,

cross-architecture API.

Update Information:

Backport fix for race condition leading to root compromise (GHSA-f55j-vvr9-69xv)

Change Log

* Wed Apr 22 2026 Neal Gompa - 1.3.4-3 - Actually apply patch for security fix * Wed Apr 22 2026 Neal Gompa - 1.3.4-2 - Backport fix for GHSA-f55j-vvr9-69xv

References


[ 1 ] Bug #2460579 - Local Privilege escalation: Run code as root due to race condition in PackageKit https://bugzilla.redhat.com/show_bug.cgi?id=2460579

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-41926fe792' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: PackageKit
Product: Fedora 42
Version: 1.3.4
Release: 3.fc42
Summary: Package management service

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here