Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

openSUSE Leap 16.0 PackageKit Moderate Authorization Issue CVE-2026-10294

opensuse
Calendar Grey July 24, 2026
Scroller Opensuse
An openSUSE update addresses a security issue in PackageKit, improving system authorization and providing bug fixes.
openSUSE has released a security update for PackageKit addressing CVE-2026-10294, which involves improper authorization, along with two bug fixes for openSUSE Leap 16.0.

Description

This update for PackageKit fixes the following issues:

Security issue fixed:

- CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250).

Non security issue fixed:

- KDE Discover ignores package locks (bsc#1263252).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1336=1

Patch

Package List

- openSUSE Leap 16.0:

PackageKit-1.2.8-160000.5.1

PackageKit-backend-dnf-1.2.8-160000.5.1

PackageKit-backend-zypp-1.2.8-160000.5.1

PackageKit-branding-upstream-1.2.8-160000.5.1

PackageKit-devel-1.2.8-160000.5.1

PackageKit-gstreamer-plugin-1.2.8-160000.5.1

PackageKit-gtk3-module-1.2.8-160000.5.1

PackageKit-lang-1.2.8-160000.5.1

libpackagekit-glib2-18-1.2.8-160000.5.1

libpackagekit-glib2-devel-1.2.8-160000.5.1

typelib-1_0-PackageKitGlib-1_0-1.2.8-160000.5.1

References

* bsc#1263252

* bsc#1267250

References:

* https://www.suse.com/security/cve/CVE-2026-10294.html

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21425-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.