{"id":235207,"date":"2026-04-24T13:28:00","date_gmt":"2026-04-24T17:28:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/04\/24\/new-pack2theroot-flaw-gives-hackers-root-linux-access\/"},"modified":"2026-04-24T14:15:10","modified_gmt":"2026-04-24T18:15:10","slug":"new-pack2theroot-flaw-gives-hackers-root-linux-access","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/04\/24\/new-pack2theroot-flaw-gives-hackers-root-linux-access\/","title":{"rendered":"New \u2018Pack2TheRoot\u2019 flaw gives hackers root Linux access"},"content":{"rendered":"<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-pack2theroot-flaw-gives-hackers-root-linux-access\/\">New \u2018Pack2TheRoot\u2019 flaw gives hackers root Linux access<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-pack2theroot-flaw-gives-hackers-root-linux-access\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/new-pack2theroot-flaw-gives-hackers-root-linux-access\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-24 13:28:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.bleepingcomputer.com\">www.bleepingcomputer.com<\/a><\/p>\n<p style=\"text-align:center\">\n<p>A new vulnerability dubbed\u00a0Pack2TheRoot could be exploited in the\u00a0PackageKit daemon to allow\u00a0local Linux users to install or remove system packages and gain root permissions.<\/p>\n<p>The flaw is identified as CVE-2026-41651 and received a medium-severity rating of 8.8 out of 10. It has persisted for almost 12 years in the PackageKit daemon,\u00a0a background service that manages software installation, updates, and removal across Linux systems.<\/p>\n<p>Earlier this week, some information about the vulnerability has been published,\u00a0along with\u00a0PackageKit version 1.3.5\u00a0that addresses the issue. However, technical details and a demo exploit have been not been disclosed to allow the patches to propagate.<\/p>\n<p> <img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/a\/as-tour-the-platform-970-x250.jpg\" alt=\"image\" style=\"margin-top: 0px;\"\/><\/p>\n<p>An investigation from the\u00a0Deutsche Telekom Red Team\u00a0uncovered that the cause of the bug is the mechanism\u00a0PackageKit uses to handle package management requests.<\/p>\n<p>Specifically, the researchers found that commands like \u2018pkcon install\u2019 could execute without requiring authentication under certain conditions on a Fedora system, allowing them to install a system package.<\/p>\n<p>Using\u00a0the Claude Opus AI tool, they further explored the potential for exploiting this behavior and discovered CVE-2026-41651.<\/p>\n<p><img decoding=\"async\" alt=\"Redacted PoC exploit for Pack2TheRoot\" height=\"600\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/April\/poc.png\" width=\"546\"\/><strong>Redacted PoC exploit for Pack2TheRoot<\/strong><br \/>Source: Deutsche Telekom<\/p>\n<h3>Impact and fixes<\/h3>\n<p>Deutsche Telekom&#8217;s Red Team reported their findings to Red Hat and PackageKit maintainers on April 8. They\u00a0state that it\u2019s safe to assume that all distributions that come with PackageKit pre-installed and enabled out-of-the-box are vulnerable to CVE-2026-41651.<\/p>\n<p>The vulnerability has been present in PackageKit\u00a0version 1.0.2, released in November 2014, and affects all versions through 1.3.4, according to the project&#8217;s security advisory.<\/p>\n<p>Researchers&#8217; testing have confirmed that an attacker could exploit the the CVE-2026-41651 vulnerability in the following Linux distributions:<\/p>\n<ul>\n<li>Ubuntu Desktop 18.04 (EOL), 24.04.4 (LTS), 26.04 (LTS beta)<\/li>\n<li>Ubuntu Server 22.04 \u2013 24.04&#8230;<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-pack2theroot-flaw-gives-hackers-root-linux-access\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New \u2018Pack2TheRoot\u2019 flaw gives hackers root Linux access https:\/\/www.bleepingcomputer.com\/news\/security\/new-pack2theroot-flaw-gives-hackers-root-linux-access\/ Publish Date: 2026-04-24 13:28:00 Source Domain:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":235208,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.bleepstatic.com\/content\/hl-images\/2025\/06\/18\/Linux_tux.jpg","fifu_image_alt":"","footnotes":""},"categories":[48],"tags":[90,31,97,89,71,94,57,79,27],"class_list":["post-235207","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","tag-cve","tag-exploit","tag-fedora","tag-flaw","tag-linux","tag-red-hat-enterprise-linux","tag-security","tag-ubuntu","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/235207"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=235207"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/235207\/revisions"}],"predecessor-version":[{"id":235209,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/235207\/revisions\/235209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/235208"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=235207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=235207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=235207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}