Path traversal in PackageKit - #VU148899
Published: September 10, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper path validation and symlink following in the PackageKit dnf5 backend and libdnf5 TempFilesMemory temporary-file tracking logic when processing crafted unauthenticated D-Bus transactions. A local user can supply a path-traversal distro identifier and create a symlink to cause a root-owned file overwrite and escalate privileges.
Exploitation requires access to the system D-Bus from a standard local user session.