Improper Verification of Cryptographic Signature in PackageKit - #VU147251

 

Improper Verification of Cryptographic Signature in PackageKit - #VU147251

Published: September 7, 2026


Vulnerability identifier: #VU147251
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to install an unsigned local package.

The vulnerability exists due to an incorrect comparison of transaction flag bitfields in the ALPM backend InstallFiles path when processing an InstallFiles transaction with ONLY_TRUSTED set. A local user can submit a local package file through the transaction to install an unsigned local package.

Exploitation requires an existing cached PolicyKit authorization for the trusted package-install action and a package file path readable by the PackageKit daemon.


Affected software

PackageKit

Remediation

Install security update from vendor's website.

PackageKit - update to 1.4.0

External References

Related Security Bulletins