https://seclists.org/oss-sec/2026/q2/201: CVE-2026-41651: TOCTOU vulnerability in PackageKit <= 1.3.4 leads to local root exploit
Published Apr 22, 2026
·Updated
Affected Software
1 affected component
PackageKit PackageKit<=1.3.4
Frequently Asked Questions
1
What is the severity of CVE-2026-41651?
CVE-2026-41651 is rated as a critical severity vulnerability due to its potential for local root exploitation.
2
How do I fix CVE-2026-41651?
To fix CVE-2026-41651, you should update to PackageKit version 1.3.5 or later, which includes the necessary security patch.
3
What type of vulnerability is CVE-2026-41651?
CVE-2026-41651 is a Time-of-check to Time-of-use (TOCTOU) vulnerability affecting PackageKit.
4
Who is affected by CVE-2026-41651?
Users of PackageKit version 1.3.4 and earlier are affected by CVE-2026-41651.
5
Can CVE-2026-41651 be exploited remotely?
No, CVE-2026-41651 is a local privilege escalation vulnerability and requires local access to the machine to exploit.