‘Pack2TheRoot’ Linux Vulnerability Enables Easy Root Privilege Escalation

A high-severity Linux vulnerability known as “Pack2TheRoot” (CVE-2026-41651) has been identified in PackageKit, a widely used package management component, allowing attackers to gain full root access on affected systems.

The flaw is caused by a time-of-check time-of-use (TOCTOU) race condition in how PackageKit handles transaction flags. This issue allows unprivileged users to manipulate package installation processes and execute actions with elevated permissions.

By exploiting this vulnerability, a local attacker can install or remove software packages without authentication, effectively bypassing security controls. This enables execution of arbitrary code with root privileges, leading to complete system compromise.

The vulnerability affects PackageKit versions from 1.0.2 to 1.3.4 and may have existed for over a decade, making it particularly concerning due to its long exposure across multiple Linux distributions, including Ubuntu, Debian, and Fedora.

Security researchers noted that the bug stems from multiple logic flaws—such as overwriting transaction flags during execution and improper state handling—which together allow attackers to inject malicious parameters into running processes.

With a CVSS score of around 8.8, the vulnerability is considered highly dangerous, especially since it requires only low-level local access and no user interaction to exploit.

A patch has been released in PackageKit version 1.3.5, and Linux distributions are rolling out updates. Experts strongly recommend immediate patching, as the flaw is easy to exploit and can grant attackers full administrative control over affected systems.

The discovery highlights ongoing risks in widely deployed system components, where even subtle race condition bugs can lead to severe privilege escalation and long-term security exposure.

 

- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

error: Content is protected !!

Share your details to download the report 2026

Share your details to download the Cybersecurity Report 2025

Share your details to download the CISO Handbook 2025

Sign Up for CXO Digital Pulse Newsletters

Share your details to download the Research Report

Share your details to download the Coffee Table Book

Share your details to download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch