Cyber Resilience
← All news

[UPDATE] [hoch] PackageKit: Schwachstelle ermöglicht Privilegieneskalation

Our takeCERT-Bund updated its advisory on a local privilege-escalation flaw in PackageKit. Update if you run it yourself.
Sources (1)
What this means for you — Security leader:Update PackageKit to a version that includes the fix for the local privilege-escalation flaw. If you run affected Linux distributions, verify the update through your package manager and restart relevant services.
What this means for you — Lean IT orgs:If your Linux systems use PackageKit, apply the available security update as soon as possible. Most small teams can do this with a single command from the terminal.
What this means for you — MSP:Check client Linux estates for PackageKit usage and push the vendor update. The flaw allows local privilege escalation; apply the patch and confirm it took on all affected systems.
What this means for you — Researcher:Review the CERT-Bund advisory for technical details on the PackageKit privilege-escalation vulnerability once more information is published.