SB2026091202 - Fedora 44 update for PackageKit
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect authorization (CVE-ID: CVE-2026-19816)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to remove installed packages.
The vulnerability exists due to incorrect authorization in the dnf5 backend RepoRemove handler when processing RepoRemove transactions with the SIMULATE flag. A local user can invoke RepoRemove with the SIMULATE flag to remove installed packages.
Only systems using the PackageKit dnf5 backend are affected. Setting autoremove to true can remove packages installed from the specified repository and sibling repository IDs sharing the same repository file.
Remediation
Install update from vendor's website.