Path: csiph.com!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: Moritz Muehlenhoff Newsgroups: linux.debian.announce.security Subject: [SECURITY] [DSA 6226-1] packagekit security update Date: Wed, 22 Apr 2026 14:30:01 +0200 Message-ID: X-Mailbox-Line: From debian-security-announce-request@lists.debian.org Wed Apr 22 12:26:46 2026 Old-Return-Path: X-Amavis-Spam-Status: No, score=-112.73 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIMWL_WL_HIGH=-0.54, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, PGPSIGNATURE=-5, RCVD_IN_DNSWL_NONE=-0.0001, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100] autolearn=ham autolearn_force=no Old-Dkim-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=LIxyUQt5F1w+0gzgZZZh9n7uHbQoOJtvNjuwhZkrprw=; b=Yk hZUmAgp9E14cO4C+yYht21YyLi6cSdsfIMiT4ZD7VigortnL8/WsmoEz2/jxMZc+cndCUGDa1eXRF tjEFpgGaN3Kgv8zlwF3HnTUSynyeLkvB6KX6wvu3GYnlChVA4gGR2k9N54CO6w02NW/wclLStK5z5 8FR72mAov9ZzeE72Q7QRlqDRMopuNQbuB9FqxA02W9F+gSJMfFEeh/OLX/edilojFGctZZCnZIYbN S4yeABIGGoq7dphzjFXlgrRddgUwROMZXfO4haB602KmcKU8InPYNL9Rwin0/ub570V7utIxs37LK wEG/BGBoz6HsZ8WxHBtt1WxsJZu6rp3w==; MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Debian: PGP check passed for security officers Priority: urgent Reply-To: debian-security-announce-request@lists.debian.org X-Mailing-List: archive/latest/5150 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/aei-cKxeJlrupNCb@seger.debian.org Approved: robomod@news.nic.it Lines: 49 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Wed, 22 Apr 2026 12:26:24 +0000 X-Original-Message-ID: Xref: csiph.com linux.debian.announce.security:4792 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6226-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff April 22, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : packagekit CVE ID : not yet available Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation. For the oldstable distribution (bookworm), this problem has been fixed in version 1.2.6-5+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1.3.1-1+deb13u1. We recommend that you upgrade your packagekit packages. For the detailed security status of packagekit please refer to its security tracker page at: https://security-tracker.debian.org/tracker/packagekit Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmnovjkACgkQEMKTtsN8 TjYg/Q//RW6Eavbeo9U+tlDtVJGltMOHeXm4NAwXa4cmdDlXfRFFyv4JGBOqF8bn qxBU051cdoMoD6AWkTjVl40iMeABPaIrc+nKY2/4mGj48FIRKoiCc6tq6iugCbEB NYx/ol+LWRsZTEIdM+ZN8YjcT/IyxWsjhzWQ3q2zSfflqlTioHY07ScjUCvVoYcg CTpVI8nFv9ToNTLENUqfAfeBmEeSl2ESaHEP926F1SXHswpXt1i+7d5KSBObidU5 HhB5fU+Q9AVMfQJhFW6MjkYVQjtwmbZS5hkhr3V7efAseRMQIDIXDddfQxeSAs7r R5jQmgth3pzQHMymk6YSqYkC3Bnr6Z9yc+AgaLbbhaZlPQBgK69WHgvg+/+YTvGc pQl7eK4eu5L0PPSLiJVOROklrG+WCu2PmuY7LVbMkdUxC5utwPdOl05VMM2+nVRJ 68xETyU9wn9TdfWzlgIac+jPEoH2WHv9nEzAYTUTxNEpqBpogEn8124ynP+72Nrn amHiDmp9WXa3y7hQd/3GoevQK2sz9634lKnYz7M0kF2T/1ha+0ye1NeG64Dvsacn 5WH+QRHnk54yS2lYqY0FpsAqGKqOtt8CG3tWTIVyDVc93FhSEZvGCHqAYbBFbzzw LlsnE+vSa77uL363oWqZqAKSTlv+1Y3LVYAHKcRqnZBETuXZWtE= =S86T -----END PGP SIGNATURE-----