<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:00:35 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:11504 — Important: PackageKit security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:11504</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: PackageKit, AlmaLinux:9: PackageKit-command-not-found, AlmaLinux:9: PackageKit-glib, AlmaLinux:9: PackageKit-glib-devel, AlmaLinux:9: PackageKit-gstreamer-plugin, AlmaLinux:9: PackageKit-gtk3-module&lt;/p&gt;
&lt;p&gt;PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PackageKit: race condition vulnerability leads to arbitrary package installation as root (CVE-2026-41651)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: PackageKit, AlmaLinux:9: PackageKit-command-not-found, AlmaLinux:9: PackageKit-glib, AlmaLinux:9: PackageKit-glib-devel, AlmaLinux:9: PackageKit-gstreamer-plugin, AlmaLinux:9: PackageKit-gtk3-module&lt;/p&gt;
&lt;p&gt;PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PackageKit: race condition vulnerability leads to arbitrary package installation as root (CVE-2026-41651)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:11504</guid>
    </item>
    <item>
      <title>bdu:2026-05781</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05781</link>
      <description>bdu:2026-05781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05781</guid>
    </item>
    <item>
      <title>EUVD-2026-337248</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337248</link>
      <description>EUVD-2026-337248</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337248</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41651</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41651</link>
      <description>&lt;p&gt;PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.&lt;/p&gt;
&lt;p&gt;A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction-&amp;gt;cached_transaction_flags`  combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`:
1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction-&amp;gt;cached_transaction_flags` without checking whether the transaction has already been  authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING.
2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags.
3. Late flag read at execution time (lines 2273–2277): The scheduler&amp;#39;s idle callback reads cached_transactio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.&lt;/p&gt;
&lt;p&gt;A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction-&amp;gt;cached_transaction_flags`  combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`:
1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction-&amp;gt;cached_transaction_flags` without checking whether the transaction has already been  authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING.
2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags.
3. Late flag read at execution time (lines 2273–2277): The scheduler&amp;#39;s idle callback reads cached_transactio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41651</guid>
    </item>
    <item>
      <title>OESA-2026-2140 — PackageKit security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2140</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: PackageKit, openEuler:24.03-LTS: PackageKit, openEuler:24.03-LTS-SP1: PackageKit, openEuler:24.03-LTS-SP3: PackageKit, openEuler:20.03-LTS-SP4: PackageKit&lt;/p&gt;
&lt;p&gt;PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distro, cross-architecture API.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;PackageKit is a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.&lt;/p&gt;
&lt;p&gt;A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction-&amp;amp;gt;cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`:
1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction-&amp;amp;gt;cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING.
2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: PackageKit, openEuler:24.03-LTS: PackageKit, openEuler:24.03-LTS-SP1: PackageKit, openEuler:24.03-LTS-SP3: PackageKit, openEuler:20.03-LTS-SP4: PackageKit&lt;/p&gt;
&lt;p&gt;PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distro, cross-architecture API.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;PackageKit is a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.&lt;/p&gt;
&lt;p&gt;A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction-&amp;amp;gt;cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`:
1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction-&amp;amp;gt;cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING.
2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2140</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10629-1 — PackageKit-1.3.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10629-1</link>
      <description>&lt;p&gt;PackageKit-1.3.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PackageKit-1.3.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10629-1</guid>
    </item>
    <item>
      <title>RHSA-2026:17558 — Red Hat Security Advisory: PackageKit security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:17558</link>
      <description>&lt;p&gt;PackageKit: race condition vulnerability leads to arbitrary package installation as root&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PackageKit: race condition vulnerability leads to arbitrary package installation as root&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:17558</guid>
    </item>
    <item>
      <title>RLSA-2026:19141 — Important: PackageKit security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:19141</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: PackageKit&lt;/p&gt;
&lt;p&gt;PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PackageKit: race condition vulnerability leads to arbitrary package installation as root (CVE-2026-41651)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: PackageKit&lt;/p&gt;
&lt;p&gt;PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PackageKit: race condition vulnerability leads to arbitrary package installation as root (CVE-2026-41651)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:19141</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1619-2 — Security update for PackageKit</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1619-2</link>
      <description>&lt;p&gt;Security update for PackageKit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for PackageKit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1619-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-41651</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41651</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: packagekit, Ubuntu:Pro:18.04:LTS: packagekit, Ubuntu:Pro:20.04:LTS: packagekit, Ubuntu:22.04:LTS: packagekit, Ubuntu:24.04:LTS: packagekit, Ubuntu:25.10: packagekit, Ubuntu:26.04:LTS: packagekit&lt;/p&gt;
&lt;p&gt;PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction-&amp;gt;cached_transaction_flags`  combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction-&amp;gt;cached_transaction_flags` without checking whether the transaction has already been  authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING. 2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags. 3. Late flag read at execution time (lines 2273–2277): The scheduler&amp;#39;s idle callback reads cached_transaction…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: packagekit, Ubuntu:Pro:18.04:LTS: packagekit, Ubuntu:Pro:20.04:LTS: packagekit, Ubuntu:22.04:LTS: packagekit, Ubuntu:24.04:LTS: packagekit, Ubuntu:25.10: packagekit, Ubuntu:26.04:LTS: packagekit&lt;/p&gt;
&lt;p&gt;PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction-&amp;gt;cached_transaction_flags`  combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction-&amp;gt;cached_transaction_flags` without checking whether the transaction has already been  authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING. 2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags. 3. Late flag read at execution time (lines 2273–2277): The scheduler&amp;#39;s idle callback reads cached_transaction…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41651</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1233 — PackageKit: Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1233</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in PackageKit ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in PackageKit ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1233</guid>
    </item>
  </channel>
</rss>
