RHSA-2026:22146: Important: PackageKit security update
PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.Security Fix(es): PackageKit: race condition vulnerability leads to arbitrary package installation as root (CVE-2026-41651) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:22146?
The severity of RHSA-2026:22146 is classified as important.
What is the main vulnerability addressed in RHSA-2026:22146?
RHSA-2026:22146 addresses a race condition vulnerability that allows arbitrary package installation as root, identified by CVE-2026-41651.
How do I fix RHSA-2026:22146?
To fix RHSA-2026:22146, you need to apply the package update for PackageKit as advised in the security announcement.
What is a race condition in the context of RHSA-2026:22146?
In the context of RHSA-2026:22146, a race condition occurs when the timing of actions leads to unexpected changes that can result in security vulnerabilities.
What systems are affected by RHSA-2026:22146?
RHSA-2026:22146 affects systems using PackageKit as a package management tool.