SB2026091203 - Fedora 45 update for PackageKit



SB2026091203 - Fedora 45 update for PackageKit

Published: September 12, 2026

Security Bulletin ID SB2026091203
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect authorization (CVE-ID: CVE-2026-19816)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to remove installed packages.

The vulnerability exists due to incorrect authorization in the dnf5 backend RepoRemove handler when processing RepoRemove transactions with the SIMULATE flag. A local user can invoke RepoRemove with the SIMULATE flag to remove installed packages.

Only systems using the PackageKit dnf5 backend are affected. Setting autoremove to true can remove packages installed from the specified repository and sibling repository IDs sharing the same repository file.


Remediation

Install update from vendor's website.