Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for PackageKit fixes the following issues:
Security issue fixed:
- CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250).
Non security issue fixed:
- KDE Discover ignores package locks (bsc#1263252).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1336=1
- openSUSE Leap 16.0:
PackageKit-1.2.8-160000.5.1
PackageKit-backend-dnf-1.2.8-160000.5.1
PackageKit-backend-zypp-1.2.8-160000.5.1
PackageKit-branding-upstream-1.2.8-160000.5.1
PackageKit-devel-1.2.8-160000.5.1
PackageKit-gstreamer-plugin-1.2.8-160000.5.1
PackageKit-gtk3-module-1.2.8-160000.5.1
PackageKit-lang-1.2.8-160000.5.1
libpackagekit-glib2-18-1.2.8-160000.5.1
libpackagekit-glib2-devel-1.2.8-160000.5.1
typelib-1_0-PackageKitGlib-1_0-1.2.8-160000.5.1
* bsc#1263252
* bsc#1267250
References:
* https://www.suse.com/security/cve/CVE-2026-10294.html
Get the latest Linux and open source security news straight to your inbox.