Improper Verification of Cryptographic Signature in PackageKit - #VU147251
Published: September 7, 2026
Vulnerability details
The vulnerability allows a local user to install an unsigned local package.
The vulnerability exists due to an incorrect comparison of transaction flag bitfields in the ALPM backend InstallFiles path when processing an InstallFiles transaction with ONLY_TRUSTED set. A local user can submit a local package file through the transaction to install an unsigned local package.
Exploitation requires an existing cached PolicyKit authorization for the trusted package-install action and a package file path readable by the PackageKit daemon.