{
  "schema_version": "1.7.0",
  "id": "RHSA-2026:11504",
  "related": [],
  "upstream": [
    "CVE-2026-41651"
  ],
  "published": "2026-04-30T10:10:38Z",
  "modified": "2026-04-30T10:10:38Z",
  "summary": "Red Hat Security Advisory: PackageKit security update",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
    }
  ],
  "affected": [
    {
      "package": {
        "name": "PackageKit",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-command-not-found",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-command-not-found"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-command-not-found-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-command-not-found-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-debugsource",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-debugsource"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-glib",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-glib"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-glib-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-glib-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-glib-devel",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-glib-devel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-gstreamer-plugin",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-gstreamer-plugin"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-gstreamer-plugin-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-gstreamer-plugin-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-gtk3-module",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-gtk3-module"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-gtk3-module-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::appstream",
        "purl": "pkg:rpm/redhat/PackageKit-gtk3-module-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-command-not-found",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-command-not-found"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-command-not-found-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-command-not-found-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-debugsource",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-debugsource"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-glib",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-glib"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-glib-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-glib-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-glib-devel",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-glib-devel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-gstreamer-plugin",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-gstreamer-plugin"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-gstreamer-plugin-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-gstreamer-plugin-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-gtk3-module",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-gtk3-module"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "name": "PackageKit-gtk3-module-debuginfo",
        "ecosystem": "Red Hat:enterprise_linux:9::crb",
        "purl": "pkg:rpm/redhat/PackageKit-gtk3-module-debuginfo"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0:1.2.6-2.el9_7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://access.redhat.com/errata/RHSA-2026:11504"
    },
    {
      "type": "ARTICLE",
      "url": "https://access.redhat.com/security/updates/classification/#important"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460604"
    },
    {
      "type": "ADVISORY",
      "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_11504.json"
    },
    {
      "type": "REPORT",
      "url": "https://access.redhat.com/security/cve/CVE-2026-41651"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41651"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41651"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L2273-L2277"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L4036"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/PackageKit/PackageKit/blob/04057883189efa225a7c785591aa87cb299782f8/src/pk-transaction.c#L873-L882"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.com/PackageKit/PackageKit/security/advisories/GHSA-f55j-vvr9-69xv"
    },
    {
      "type": "ARTICLE",
      "url": "https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html"
    }
  ]
}