Back github.security.telekom.com Deutsche Telekom Red Team
Today we publicly disclose a high-severity vulnerability (CVSS 3.1: 8.8) - in coordination with distro maintainers - that affects multiple Linux distributions in their default installations. The Pack2TheRoot vulnerability can be exploited by any local unprivileged user to obtain root access on a vulnerable system.
The vulnerability lies in the PackageKit daemon , a cross-distro package management abstraction layer.
The vulnerability enables an unprivileged attacker to install or remove system packages without authorization. This can be exploited to gain full root access or compromise the system in other ways.
The Pack2TheRoot (CVE-2026-41651) vulnerability was discovered by Deutsche Telekom’s Red Team during targeted research into local privilege escalation vectors on modern Linux systems. PackageKit as a candidate initially caught our attention when we observed that a pkcon install command could install a system package without requiring a password on a Fedora Workstation. Starting in 2025, we began investigating whether this behavior could be abused to achieve arbitrary package installation. By guiding the AI-assisted research into a specific direction (using Claude Opus by Anthropic) we were able to discover an exploitable vulnerability. The finding was manually reviewed and verified before being responsibly reported to the PackageKit maintainers, who confirmed the issue and its exploitability.
All PackageKit versions between >= 1.0.2 and = 1.3.3 use pkgcli monitor to test for output.
Despite of the fixed release 1.3.5 , multiple Distributions released patched packages. In the following, we link the Distros package overviews, that show Distro specific patched versions.
Even though the vulnerability is reliably exploitable in seconds, it leaves traces that serve as a strong indicator of compromise. After successful exploitation, the PackageKit daemon hits an assertion failure and crashes. Systemd recovers the daemon on the D-Bus invocation, preventing a denial-of-service, but the crash is observable in the system logs:
We currently do not technical details on the root cause of the vulnerability. We plan to add them at a later point in time here.
We have developed a working proof-of-concept that reliably exploits this vulnerability to achieve root code execution from an unprivileged local user on default installations of various distributions. However, the PoC code is not being shared publicly at this time for obvious reasons.
A huge thank you goes to PackageKit maintainer Matthias Klumpp ( @ximion ), for addressing this vulnerability quickly by creating a patch and for coordinating communication with the distribution maintainers. The vulnerability has been found and reported by Deutsche Telekom’s Red Team. If you have questions regarding the vulnerability or are interested in our security offerings , including Red Team assessments, feel free to [loading (JS)…] .
The images in this article are free to use, as long as a reference to this blog post is provided. A SVG version of the Pack2TheRoot Logo is also available.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
