VendorsPackageKit Projectpackagekitall versions
Vulnerabilities

PackageKit Project PackageKit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-41651
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
Published 2026-04-22 · Modified
8.8EPSS 0.002
CVE-2020-16122
Packagekit's apt backend lets user install untrusted local packages
Published 2020-11-07 · Modified
8.2EPSS 0.003
CVE-2018-1106
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
Published 2018-04-23 · Modified
5.5EPSS 0.004
CVE-2011-2515
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.
Published 2019-11-27 · Modified
5.3EPSS 0.004
CVE-2020-16121
PackageKit error messages leak presence and mimetype of files to unprivileged users
Published 2020-11-07 · Modified
3.3EPSS 0.005
CVE-2022-0987
A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.
Published 2022-06-28 · Modified
3.3EPSS 0.003
CVE-2024-0217
Packagekitd: use-after-free in idle function callback
Published 2024-01-03 · Modified
3.3EPSS 0.002
CVE-2013-1764
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
Published 2014-04-16 · Modified
2.1EPSS 0.004