Improper Authorization in PackageKit - #VU148898
Published: September 10, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to missing enforcement of trusted package requirements in the PackageKit dnf5 backend transaction handling when processing trusted update transactions for staged @commandline RPMs. A local user can stage an unsigned local RPM and request a trusted update to escalate privileges.
Exploitation requires an active local-console session; an SSH-only session is insufficient.