CVE-2026-41651

high
Published 2026-04-29 · Modified 2026-05-26
CVSS v3
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2
VIR risk
8.8

Description

Important: PackageKit security update

Predictions

Exploit likelihood
82%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-19354.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-11504.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-11635.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2460604

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:11635

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-41651

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-41651.html

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2026/04/22/6

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/PackageKit/PackageKit/security/advisories/GHSA-f55j-vvr9-69xv

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:19354

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:11504

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
suse slesaffected
debian debianbookwormfixed1.2.6-5+deb12u1
debian debianbullseyefixed1.2.2-2+deb11u1
debian debianforkyfixed1.3.5-1
debian debiansidfixed1.3.5-1
debian debiantrixiefixed1.3.1-1+deb13u1

Application impact

VendorProductVersionsFixed
packagekit_projectpackagekit{"startIncluding":"1.0.2","endExcluding":"1.3.5"}1.3.5

References

CWEs

CWE-367

Verify integrity in audit chain (admin only). AS-IS.