Twelve-year-old PackageKit flaw affects widely used Linux distributions

Deutsche Telekom's red team has found a privilege escalation vulnerability rated CVSS 8.8 in the PackageKit daemon used by several widely deployed Linux distributions. The researchers used Anthropic's Claude Opus to locate the flaw before reviewing and verifying the finding manually. All distributions with PackageKit installed and enabled are expected to be vulnerable. Tested and confirmed are Ubuntu Desktop 18.04, 24.04.4 LTS and 26.04 LTS beta, Ubuntu Server 22.04 to 24.04 LTS, Debian Desktop Trixie 13.4, RockyLinux Desktop 10.1, and Fedora 43 Desktop and Server. The finding followed responsible disclosure procedures and PackageKit 1.3.5 addresses the issue.

What this means for your organisation

Privilege escalation is rarely the front door, but it is almost always the next step once an attacker has a foothold. A flaw that has been present for twelve years turns up everywhere from developer workstations to servers nobody has touched in years. That the finding came with help from a language model is worth management's attention: methods for finding bugs are getting cheaper and faster, and that applies to both sides of the table.

Berigo recommends

  • Deploy PackageKit 1.3.5 across all Linux machines, including workstations that rarely enter the patch cycle.
  • Disable PackageKit on systems where the service is not needed for operations.
  • Identify Linux systems not covered by central patching today and bring them into the scheme.
  • Reflect in your risk assessment that machine-assisted bug hunting lowers the bar for finding old flaws in widely used software.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch