ELA-1693-1 packagekit security update

local privilege escalation

2026-04-22
Packagepackagekit
Version1.1.5-2+deb9u3 (stretch), 1.1.12-5+deb10u1 (buster)


Maik Schaefer discovered that a TOCTOU race condition in PackageKit (a package management service over a DBus interface) could result in local privilege escalation.



For Debian 10 buster, these problems have been fixed in version 1.1.12-5+deb10u1.

For Debian 9 stretch, these problems have been fixed in version 1.1.5-2+deb9u3.

We recommend that you upgrade your packagekit packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.