Improper Neutralization of Argument Delimiters in a Command in PackageKit - #VU148897
Published: September 10, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code as root.
The vulnerability exists due to improper neutralization of argument delimiters in the PackageKit spawn dispatcher command stream when processing SearchNames D-Bus requests. A local user can send a SearchNames value containing control characters to inject a privileged backend command and execute arbitrary code as root.
Exploitation requires a reused backend helper and a Python-dispatcher spawn backend, such as eopkg, pisi, entropy, or portage.