A local privilege escalation flaw in PackageKit tracked as CVE-2026-41651 allows an unprivileged user to exploit a time-of-check/time-of-use race condition and install or remove arbitrary packages with root privileges. The issue, dubbed Pack2TheRoot, affects PackageKit versions 1.0.2 through 1.3.4 and was discovered by Deutsche Telekom’s Red Team during research into Linux privilege-escalation paths. Researchers said exploitability was confirmed on default installations using both apt and dnf backends, including Ubuntu, Debian, Rocky Linux, and Fedora, indicating broad exposure across Linux distributions.
PackageKit 1.3.5 fixes the vulnerability, and maintainers said Linux distributors were notified in advance so updates could be prepared before public disclosure. A GitHub Security Advisory, Telekom’s technical write-up, an oss-sec disclosure, and a Debian security update were released as patches became available, while some technical details were initially withheld to reduce the risk of immediate weaponization. Because the vulnerable code path dates back more than a decade, the flaw may affect a wide installed base on systems where PackageKit is present and unpatched.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Deutsche Telekom researchers published a proof of concept for CVE-2026-41651, demonstrating how the PackageKit TOCTOU flaw could be exploited for local privilege escalation to root. They also noted exploitation may leave forensic evidence because PackageKit often crashes and logs an assertion failure after the exploit runs.
Debian published security advisory DSA-6226-1 to distribute a PackageKit security update addressing CVE-2026-41651. This marked downstream remediation for Debian systems affected by the vulnerability.
Telekom Security published a blog post on Pack2TheRoot, identifying the issue as CVE-2026-41651 and describing it as a cross-distribution local privilege escalation vulnerability. The post accompanied public disclosure of the flaw and fix.
A GitHub Security Advisory documented the Pack2TheRoot vulnerability, affected PackageKit versions, and the patched release 1.3.5. The advisory highlighted the broad attack surface due to the flaw existing since PackageKit 1.0.2.
PackageKit version 1.3.5 was released as the patched version for the local privilege escalation vulnerability affecting versions 1.0.2 through 1.3.4. The fix addressed the race condition that allowed arbitrary package installation as root.
Matthias Klumpp publicly disclosed CVE-2026-41651 on the oss-sec mailing list, describing a TOCTOU vulnerability in PackageKit up to and including version 1.3.4 that could let a local user install or remove arbitrary packages and gain root. The disclosure noted that full technical details were being limited initially to give users time to update.
Before public disclosure, distributors were notified through direct outreach and the distros@ coordination channel so patched packages could be prepared. This coordinated disclosure preceded the public release of technical details and fixes.
Deutsche Telekom’s Red Team identified a time-of-check/time-of-use race condition in PackageKit, later named Pack2TheRoot, during research into local privilege escalation paths on Linux. The flaw was confirmed as exploitable on default installations using apt and dnf backends across Ubuntu, Debian, Rocky Linux, and Fedora.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
14 references tracked. Mallory keeps watching after this page renders.
hackers-arise.com
Open sourcecsirt.sk
Open sourcehackread.com
Open sourcescworld.com
Open sourcegithub.security.telekom.com
Open sourcegithub.com
Open sourceseclists.org
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.