Our takeCERT-Bund updated its advisory on a local privilege-escalation flaw in PackageKit. Update if you run it yourself.Cyber Resilience desk
Sources (1)
- cert_bund · cert_bund
What this means for you — Security leader:Update PackageKit to a version that includes the fix for the local privilege-escalation flaw. If you run affected Linux distributions, verify the update through your package manager and restart relevant services.
What this means for you — Lean IT orgs:If your Linux systems use PackageKit, apply the available security update as soon as possible. Most small teams can do this with a single command from the terminal.
What this means for you — MSP:Check client Linux estates for PackageKit usage and push the vendor update. The flaw allows local privilege escalation; apply the patch and confirm it took on all affected systems.
What this means for you — Researcher:Review the CERT-Bund advisory for technical details on the PackageKit privilege-escalation vulnerability once more information is published.