OVERVIEW CVE-2026-41651 is a time-of-check time-of-use (TOCTOU) race condition vulnerability affecting PackageKit versions 1.0.2 through 1.3.4. PackageKit is a D-Bus abstraction layer used across Linux distributions for package management. The vulnerability allows unprivileged local users to install arbitrary RPM packages with root privileges by exploiting a race condition in transaction flag handling, leading to local privilege escalation. The issue stems from three distinct bugs in the transaction processing code that allow flag overwrites during active transactions and delayed flag validation. PackageKit has addressed this vulnerability in version 1.3.5. SEVERITY This vulnerability carries a CVSS v3.1 score of 8.8 (HIGH) with a local attack vector requiring low complexity and no user interaction. The threat model requires low privileges and affects the confidentiality, integrity, and availability of the system. An attacker can exploit this flaw to execute arbitrary RPM scriptlets as root without authentication, providing complete system compromise capabilities. The vulnerability is particularly concerning because it requires no special conditions beyond local access and minimal complexity to execute. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. No CVE Entry (KEV) designation has been assigned, and the vulnerability does not appear on industry hot lists. The EPSS score of 0.000250 indicates minimal current exploitation probability. However, given the high severity rating and straightforward nature of the attack requiring only local access, organizations should prioritize patching before public exploit code becomes widely available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.2, < 1.3.5CPE matchmatch criteria | cpe:2.3:a:packagekit_project:packagekit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.