Important: PackageKit security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11635", "synopsis": "Important: PackageKit security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for PackageKit.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.\n\nSecurity Fix(es):\n\n* PackageKit: race condition vulnerability leads to arbitrary package installation as root (CVE-2026-41651)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2460604", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2460604", "description": ""}], "cves": [{"name": "CVE-2026-41651", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41651", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-367"}], "references": [], "publishedAt": "2026-04-30T18:01:05.380956Z", "rpms": {"Rocky Linux 8": {"nvras": ["PackageKit-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-0:1.1.12-8.el8_10.i686.rpm", "PackageKit-0:1.1.12-8.el8_10.src.rpm", "PackageKit-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-command-not-found-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-command-not-found-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-command-not-found-debuginfo-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-command-not-found-debuginfo-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-cron-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-cron-0:1.1.12-8.el8_10.x86_64.rpm","PackageKit-debuginfo-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-debuginfo-0:1.1.12-8.el8_10.i686.rpm", "PackageKit-debuginfo-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-debugsource-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-debugsource-0:1.1.12-8.el8_10.i686.rpm", "PackageKit-debugsource-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-glib-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-glib-0:1.1.12-8.el8_10.i686.rpm", "PackageKit-glib-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-glib-debuginfo-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-glib-debuginfo-0:1.1.12-8.el8_10.i686.rpm", "PackageKit-glib-debuginfo-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-glib-devel-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-glib-devel-0:1.1.12-8.el8_10.i686.rpm", "PackageKit-glib-devel-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-gstreamer-plugin-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-gstreamer-plugin-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-gstreamer-plugin-debuginfo-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-gstreamer-plugin-debuginfo-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-gtk3-module-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-gtk3-module-0:1.1.12-8.el8_10.i686.rpm", "PackageKit-gtk3-module-0:1.1.12-8.el8_10.x86_64.rpm", "PackageKit-gtk3-module-debuginfo-0:1.1.12-8.el8_10.aarch64.rpm", "PackageKit-gtk3-module-debuginfo-0:1.1.12-8.el8_10.i686.rpm", "PackageKit-gtk3-module-debuginfo-0:1.1.12-8.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important PackageKit security update released for Rocky Linux addressing race condition risks. Act promptly!. PackageKit security, Rocky Linux update, security advisory, package management risk. . Severity: Important. LinuxSecurity.com Team
Important: PackageKit security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11504", "synopsis": "Important: PackageKit security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for PackageKit.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.\n\nSecurity Fix(es):\n\n* PackageKit: race condition vulnerability leads to arbitrary package installation as root (CVE-2026-41651)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2460604", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2460604", "description": ""}], "cves": [{"name": "CVE-2026-41651", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41651", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-367"}], "references": [], "publishedAt": "2026-04-30T12:03:33.126838Z", "rpms": {"Rocky Linux 9": {"nvras": ["PackageKit-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-0:1.2.6-2.el9_7.src.rpm", "PackageKit-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-command-not-found-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-command-not-found-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-command-not-found-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-command-not-found-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-command-not-found-debuginfo-0:1.2.6-2.el9_7.aarch64.rpm","PackageKit-command-not-found-debuginfo-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-command-not-found-debuginfo-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-command-not-found-debuginfo-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-debuginfo-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-debuginfo-0:1.2.6-2.el9_7.i686.rpm", "PackageKit-debuginfo-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-debuginfo-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-debuginfo-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-debugsource-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-debugsource-0:1.2.6-2.el9_7.i686.rpm", "PackageKit-debugsource-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-debugsource-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-debugsource-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-glib-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-glib-0:1.2.6-2.el9_7.i686.rpm", "PackageKit-glib-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-glib-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-glib-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-glib-debuginfo-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-glib-debuginfo-0:1.2.6-2.el9_7.i686.rpm", "PackageKit-glib-debuginfo-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-glib-debuginfo-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-glib-debuginfo-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-glib-devel-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-glib-devel-0:1.2.6-2.el9_7.i686.rpm", "PackageKit-glib-devel-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-glib-devel-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-glib-devel-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-gstreamer-plugin-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-gstreamer-plugin-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-gstreamer-plugin-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-gstreamer-plugin-debuginfo-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-gstreamer-plugin-debuginfo-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-gstreamer-plugin-debuginfo-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-gtk3-module-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-gtk3-module-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-gtk3-module-0:1.2.6-2.el9_7.s390x.rpm","PackageKit-gtk3-module-0:1.2.6-2.el9_7.x86_64.rpm", "PackageKit-gtk3-module-debuginfo-0:1.2.6-2.el9_7.aarch64.rpm", "PackageKit-gtk3-module-debuginfo-0:1.2.6-2.el9_7.ppc64le.rpm", "PackageKit-gtk3-module-debuginfo-0:1.2.6-2.el9_7.s390x.rpm", "PackageKit-gtk3-module-debuginfo-0:1.2.6-2.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. PackageKit security update available for Rocky Linux 9. Immediate action needed against important race condition issue.. PackageKit Update, Rocky Linux Security, Important Security Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.