INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Pack2TheRoot bug lets Linux users gain root privileges easily
| 2026-04-24 19:46 HIGH HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A 12-year-old vulnerability, tracked as CVE-2026-41651, was recently discovered by Deutsche Telekom's Red Team and disclosed to maintainers. The Pack2TheRoot flaw allows unprivileged users to install or remove system packages without authorization on vulnerable Linux systems, potentially gaining full root access. This high-severity vulnerability affects multiple Linux distributions in their default installations, including Ubuntu, Debian, Fedora, and Rocky Linux, with all PackageKit versions from 1.0.2 to 1.3.4 being at risk for over a decade. The issue was fixed in version 1.3.5 of PackageKit, which was released on April 22, 2026, but researchers have developed a reliable proof-of-concept that allows an unprivileged local user to gain root code execution on default Linux systems.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-41651 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-41651CVE-2026-41651
Target & Sectors
Global Scope
Incident Timeline
April 22, 2026
Researchers developed a proof-of-concept that allows an unprivileged local user to gain root code execution on default Linux systems using the 12-year-old Pack2TheRoot bug.
Click on any entity below to view its context and source!
infrastructure
Linux
Researchers have developed a reliable proof-of-concept that allows an unprivileged local user to gain root code execution on default Linux systems.
infrastructure
1.3.5
Although fixed in version 1.3.5, many distributions have released patched versions separately, so updating via your distro is essential.
2026/04/24
Threat actors can exploit the 12-year-old Pack2TheRoot bug in PackageKit versions 1.0.2 to 1.3.4, allowing local Linux users to gain root privileges without authorization.
Click on any entity below to view its context and source!
infrastructure
Linux
12-year-old Pack2TheRoot bug lets Linux users gain root privileges.
12-year-old Pack2TheRoot bug lets Linux users gain root privileges
‘Pack2TheRoot’ flaw lets local Linux users gain root via PackageKit.
“Today we publicly disclose a high-severity vulnerability (CVSS 3.1: 8.8) – in coordination with distro maintainers – that affects multiple Linux distributions in their default installations.
All PackageKit versions from 1.0.2 to 1.3.4 are vulnerable, affecting many Linux distributions for over 12 years.
Tested systems include Ubuntu, Debian, Fedora, and Rocky Linux, and others using PackageKit may also be at risk, including servers with Cockpit.
New ‘Pack2TheRoot’ flaw gives hackers root Linux access.
A new vulnerability dubbed Pack2TheRoot could be exploited in the PackageKit daemon to allow local Linux users to install or remove system packages and gain root permissions.
It has persisted for almost 12 years in the PackageKit daemon, a background service that manages software installation, updates, and removal across Linux systems.
Researchers' testing have confirmed that an attacker could exploit the the CVE-2026-41651 vulnerability in the following Linux distributions:
Ubuntu Desktop 18.04 (EOL), 24.04.4 (LTS), 26.04 (LTS beta)
Ubuntu Server 22.04 – 24.04 (LTS)
Debian Desktop Trixie 13.4
RockyLinux Desktop 10.1
Fedora 43 Desktop
Fedora 43 Server
The list is not exhaustive, though, and any Linux distribution using PackageKit should be treated as potentially vulne…
infrastructure
1.0.2
All PackageKit versions from 1.0.2 to 1.3.4 are vulnerable, affecting many Linux distributions for over 12 years.
The vulnerability has been present in PackageKit version 1.0.2, released in November 2014, and affects all versions through 1.3.4, according to the project's
security advisory
.
infrastructure
1.3.4
All PackageKit versions from 1.0.2 to 1.3.4 are vulnerable, affecting many Linux distributions for over 12 years.
The vulnerability has been present in PackageKit version 1.0.2, released in November 2014, and affects all versions through 1.3.4, according to the project's
security advisory
.
infrastructure
1.3.5
The issue is fixed in version 1.3.5, with patches released on April 22, 2026.
Earlier this week, some information about the vulnerability has been published, along with
PackageKit version 1.3.5
that addresses the issue.
Users should upgrade to PackageKit version 1.3.5 as soon as possible, and ensure that any other software using the package as a dependency has been moved to a safe release.
infrastructure
22.04 Ubuntu Server
Ubuntu Server 22.04 – 24.04 (LTS)
Debian Desktop Trixie 13.4
RockyLinux Desktop 10.1
Fedora 43 Desktop
Fedora 43 Server
The list is not exhaustive, though, and any Linux distribution using PackageKit should be treated as potentially vulner…
infrastructure
24.04 Ubuntu Server
Ubuntu Server 22.04 – 24.04 (LTS)
Debian Desktop Trixie 13.4
RockyLinux Desktop 10.1
Fedora 43 Desktop
Fedora 43 Server
The list is not exhaustive, though, and any Linux distribution using PackageKit should be treated as potentially vulner…
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
12-year-old Pack2TheRoot bug lets Linux users gain root privileges.
12-year-old Pack2TheRoot bug lets Linux users gain root privileges
‘Pack2TheRoot’ flaw lets local Linux users gain root via PackageKit.
“Today we publicly disclose a high-severity vulnerability (CVSS 3.1: 8.8) – in coordination with distro maintainers – that affects multiple Linux distributions in their default installations.
All PackageKit versions from 1.0.2 to 1.3.4 are vulnerable, affecting many Linux distributions for over 12 years.
Tested systems include Ubuntu, Debian, Fedora, and Rocky Linux, and others using PackageKit may also be at risk, including servers with Cockpit.
Researchers have developed a reliable proof-of-concept that allows an unprivileged local user to gain root code execution on default Linux systems.
New ‘Pack2TheRoot’ flaw gives hackers root Linux access.
A new vulnerability dubbed Pack2TheRoot could be exploited in the PackageKit daemon to allow local Linux users to install or remove system packages and gain root permissions.
It has persisted for almost 12 years in the PackageKit daemon, a background service that manages software installation, updates, and removal across Linux systems.
Researchers' testing have confirmed that an attacker could exploit the the CVE-2026-41651 vulnerability in the following Linux distributions:
Ubuntu Desktop 18.04 (EOL), 24.04.4 (LTS), 26.04 (LTS beta)
Ubuntu Server 22.04 – 24.04 (LTS)
Debian Desktop Trixie 13.4
RockyLinux Desktop 10.1
Fedora 43 Desktop
Fedora 43 Server
The list is not exhaustive, though, and any Linux distribution using PackageKit should be treated as potentially vulne…
Metrics
infrastructure
1.0.2
Software Version
All PackageKit versions from 1.0.2 to 1.3.4 are vulnerable, affecting many Linux distributions for over 12 years.
The vulnerability has been present in PackageKit version 1.0.2, released in November 2014, and affects all versions through 1.3.4, according to the project's
security advisory
.
Metrics
infrastructure
1.3.4
Software Version
All PackageKit versions from 1.0.2 to 1.3.4 are vulnerable, affecting many Linux distributions for over 12 years.
The vulnerability has been present in PackageKit version 1.0.2, released in November 2014, and affects all versions through 1.3.4, according to the project's
security advisory
.
Metrics
infrastructure
1.3.5
Software Version
The issue is fixed in version 1.3.5, with patches released on April 22, 2026.
Although fixed in version 1.3.5, many distributions have released patched versions separately, so updating via your distro is essential.
Earlier this week, some information about the vulnerability has been published, along with
PackageKit version 1.3.5
that addresses the issue.
Users should upgrade to PackageKit version 1.3.5 as soon as possible, and ensure that any other software using the package as a dependency has been moved to a safe release.
Metrics
infrastructure
22
Ubuntu Server
Ubuntu Server 22.04 – 24.04 (LTS)
Debian Desktop Trixie 13.4
RockyLinux Desktop 10.1
Fedora 43 Desktop
Fedora 43 Server
The list is not exhaustive, though, and any Linux distribution using PackageKit should be treated as potentially vulner…
Metrics
infrastructure
24
Ubuntu Server
Ubuntu Server 22.04 – 24.04 (LTS)
Debian Desktop Trixie 13.4
RockyLinux Desktop 10.1
Fedora 43 Desktop
Fedora 43 Server
The list is not exhaustive, though, and any Linux distribution using PackageKit should be treated as potentially vulner…
Intelligence Sources
Security Affairs
2026-04-24
12-year-old Pack2TheRoot bug lets Linux users gain root privileges
Security Affairs
BleepingComputer
2026-04-24
New ‘Pack2TheRoot’ flaw gives hackers root Linux access
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:08
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
PackageKit
entity
10x
timeline
Temporal Reference
April 22, 2026
date
3x
infrastructure
Software Version
1.0.2
version
2x
vulnerability
CVSS Score
9
score
2x
infrastructure
Ubuntu Server
22
ubuntu server
Contextual Telemetry
Context Block
8 METRICS
infrastructure
Affected Product
Linux
software
vulnerability
Exploited CVE
CVE-2026-41651
cve
general metric
Severity Vulnerability
9
severity vulnerability
general metric
Testing
18
testing
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
general metric
Rockylinux Desktop
13
rockylinux desktop
general metric
Desktop Fedora
43
desktop fedora
general metric
May
14
may
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.