#packagekit — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #packagekit, aggregated by home.social.
-
fed up with #packagekit. first masked it, but now uninstalled it. just doing zypper dup
-
fed up with #packagekit. first masked it, but now uninstalled it. just doing zypper dup
-
pkgcli rinnova l’esperienza di PackageKit con comandi più intuitivi, output moderno e supporto JSON per automazione e scripting.
#pkgcli #Linux #PackageKit #OpenSource #Terminale #SysAdmin #LinuxDesktop #SoftwareLibero
-
pkgcli rinnova l’esperienza di PackageKit con comandi più intuitivi, output moderno e supporto JSON per automazione e scripting.
#pkgcli #Linux #PackageKit #OpenSource #Terminale #SysAdmin #LinuxDesktop #SoftwareLibero
-
I'm rather late writing about a feature released a while ago, but a lot of people didn't know about `pkgcli` yet, and why i exists. So, enjoy this short introduction to a modern #PackageKit command-line frontend! 😁
-
I'm rather late writing about a feature released a while ago, but a lot of people didn't know about `pkgcli` yet, and why i exists. So, enjoy this short introduction to a modern #PackageKit command-line frontend! 😁
-
37 Debian LTS advisories were released in February fixing 145 CVEs across various packages. These include security fixes for bind9, firefox-esr, imagemagick, libpng, mbedtls, openssh, packagekit, perl, postgresql-13, python3.9, systemd and many more.
Debian LTS contributors also prepared updates for more recent releases, Debian 12 (#bookworm), Debian 13 (#trixie) and Debian unstable.
Read the full report: https://www.freexian.com/blog/debian-lts-report-2026-04/?utm_source=mastodon&utm_medium=social
This work is funded by Freexian's Debian LTS offering. Become a sponsor of Debian LTS (https://www.freexian.com/lts/debian/?utm_source=mastodon&utm_medium=social) and enjoy the benefits (https://www.freexian.com/lts/debian/details/#benefits).
#debian #debianlts #freexian #imagemagick #libpng #openssh #packagekit #perl #systemd
-
37 Debian LTS advisories were released in February fixing 145 CVEs across various packages. These include security fixes for bind9, firefox-esr, imagemagick, libpng, mbedtls, openssh, packagekit, perl, postgresql-13, python3.9, systemd and many more.
Debian LTS contributors also prepared updates for more recent releases, Debian 12 (#bookworm), Debian 13 (#trixie) and Debian unstable.
Read the full report: https://www.freexian.com/blog/debian-lts-report-2026-04/?utm_source=mastodon&utm_medium=social
This work is funded by Freexian's Debian LTS offering. Become a sponsor of Debian LTS (https://www.freexian.com/lts/debian/?utm_source=mastodon&utm_medium=social) and enjoy the benefits (https://www.freexian.com/lts/debian/details/#benefits).
#debian #debianlts #freexian #imagemagick #libpng #openssh #packagekit #perl #systemd
-
📢⚠️ #Pack2TheRoot exposes a 12-year-old flaw in Linux’s PackageKit, letting unprivileged users gain root access in seconds. Affects major distros, patch now
Read: https://hackread.com/pack2theroot-linux-packagekit-flaw-full-compromise/
-
📢⚠️ #Pack2TheRoot exposes a 12-year-old flaw in Linux’s PackageKit, letting unprivileged users gain root access in seconds. Affects major distros, patch now
Read: https://hackread.com/pack2theroot-linux-packagekit-flaw-full-compromise/
-
Article sur une faille sur #PackageKit :
https://goodtech.info/pack2theroot-faille-linux-packagekit-root-cve-2026-41651/
Pour info packagekit est traduit en :
- Kabyle : 31%
- Occitan : 27%
- Breton : 22%- Basque, Galicien, Catalan : +60%
-
Article sur une faille sur #PackageKit :
https://goodtech.info/pack2theroot-faille-linux-packagekit-root-cve-2026-41651/
Pour info packagekit est traduit en :
- Kabyle : 31%
- Occitan : 27%
- Breton : 22%- Basque, Galicien, Catalan : +60%
-
„ #Pack2TheRoot “: #Sicherheitslücke betrifft mehrere #Linux-Distributionen.
Das #Telekom- #Sicherheitsteam hat die Sicherheitslücke „Pack2TheRoot“ entdeckt, die #Rechteausweitung in mehreren #Distributionen ermöglicht.
Das meldet die Telekom auf ihren Sicherheitsseiten. #PackageKit ist ein #Abstraktions_Layer für #D_Bus zum eigentlich sicheren Verwalten von Paketen für beliebige #Distributionen und #Architekturen...
-
„ #Pack2TheRoot “: #Sicherheitslücke betrifft mehrere #Linux-Distributionen.
Das #Telekom- #Sicherheitsteam hat die Sicherheitslücke „Pack2TheRoot“ entdeckt, die #Rechteausweitung in mehreren #Distributionen ermöglicht.
Das meldet die Telekom auf ihren Sicherheitsseiten. #PackageKit ist ein #Abstraktions_Layer für #D_Bus zum eigentlich sicheren Verwalten von Paketen für beliebige #Distributionen und #Architekturen...
-
#Linux #packagekit #vulnerability
В демоне PackageKit обнаружена новая уязвимость, получившая название #Pack2TheRoot, которая позволяет локальным пользователям Linux устанавливать или удалять системные пакеты и получать права root.
Уязвимость #CVE-2026-41651 (CVSS 8,8 из 10) существует в демоне PackageKit уже почти 12 лет.
Обновление PackageKit до v.1.3.5 устраняет уязвимость. Однако технические подробности и PoC до сих пор не раскрыты, оставляя временной лаг для распространения исправлений.
Согласно расследованию Deutsche Telekom, причиной ошибки является механизм, используемый PackageKit для обработки запросов на управление пакетами.
В частности, исследователи обнаружили, что команды типа `pkcon install` могут выполняться без аутентификации при определённых условиях в системе Fedora, что позволяет им устанавливать системный пакет.
-
#Linux #packagekit #vulnerability
В демоне PackageKit обнаружена новая уязвимость, получившая название #Pack2TheRoot, которая позволяет локальным пользователям Linux устанавливать или удалять системные пакеты и получать права root.
Уязвимость #CVE-2026-41651 (CVSS 8,8 из 10) существует в демоне PackageKit уже почти 12 лет.
Обновление PackageKit до v.1.3.5 устраняет уязвимость. Однако технические подробности и PoC до сих пор не раскрыты, оставляя временной лаг для распространения исправлений.
Согласно расследованию Deutsche Telekom, причиной ошибки является механизм, используемый PackageKit для обработки запросов на управление пакетами.
В частности, исследователи обнаружили, что команды типа `pkcon install` могут выполняться без аутентификации при определённых условиях в системе Fedora, что позволяет им устанавливать системный пакет.
-
⚠️🔒 "Pack2TheRoot" erlaubt laut Telekom‑Security in PackageKit eine Privilegien‑Escalation (TOCTOU, CVE‑2026‑41651, CVSS 8.8). Mehrere Standard‑Distros betroffen — Update auf PackageKit ≥1.3.5 und zeitnahe System‑Patches empfohlen. https://www.heise.de/news/Pack2TheRoot-Sicherheitsluecke-betrifft-mehrere-Linux-Distributionen-11272897.html #Pack2TheRoot #Linux #Security #PackageKit 🐧
-
⚠️🔒 "Pack2TheRoot" erlaubt laut Telekom‑Security in PackageKit eine Privilegien‑Escalation (TOCTOU, CVE‑2026‑41651, CVSS 8.8). Mehrere Standard‑Distros betroffen — Update auf PackageKit ≥1.3.5 und zeitnahe System‑Patches empfohlen. https://www.heise.de/news/Pack2TheRoot-Sicherheitsluecke-betrifft-mehrere-Linux-Distributionen-11272897.html #Pack2TheRoot #Linux #Security #PackageKit 🐧
-
Na gut dass Nix kein #PackageKit unterstützt…
(edit: Nix, nicht NixOS)https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html
-
🔓 Root sur Linux en 2 secondes ? C'est la faille Pack2TheRoot
https://goodtech.info/pack2theroot-faille-linux-packagekit-root-cve-2026-41651/
> Une vulnérabilité de 12 ans vient d'être déterrée dans #PackageKit. #Ubuntu, #Fedora, #Debian... presque tout le monde est concerné. Patch disponible (ouf !). #linux
-
Discover the Pack2TheRoot flaw, a high-severity vulnerability (CVE-2026-41651) in PackageKit that has granted local users root access on Linux systems for nearly 12 years. This incident, where AI helped uncover the bug, forces a critical reevaluation of how we audit foundational open-source components. Learn which distributions are affected and why immediate patching to PackageKit 1.3.5 is…
#cybersecurity #pack2theroot #packagekit
🤖 This post was AI-generated.
-
Linux Flaw Exposes Users to Root Access Attacks
A major Linux flaw, dubbed "Pack2TheRoot," has been hiding in plain sight for 12 years, allowing attackers with local access to gain root permissions and wreak havoc on your system - but a patch has finally been released to squash it. This medium-severity vulnerability, scoring 8.8 out of 10, highlights the importance of staying on top of software…
#LinuxFlaw #RootAccess #Cve202641651 #Packagekit #ElevationOfPrivilege
-
Forscher der Deutschen Telekom haben eine kritische #Sicherheitslücke unter #Linux gefunden. Über #PackageKit können Angreifer Root-Zugriff erlangen. Potenziell betroffen sind Distros wie #Ubuntu und #Debian. https://winfuture.de/news,158305.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Forscher der Deutschen Telekom haben eine kritische #Sicherheitslücke unter #Linux gefunden. Über #PackageKit können Angreifer Root-Zugriff erlangen. Potenziell betroffen sind Distros wie #Ubuntu und #Debian. https://winfuture.de/news,158305.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Here's a harmless little #PoC for the #PackageKit LPE vulnerability (CVE-2026-41651), by @br3zel and myself: https://codeberg.org/hillu/cve-2026-41651-poc
It was a lot of fun to piece together. -
Forgot your root password? No problem! With #PackageKit <= 1.3.4 you can do all the fun root action on any Linux system you have local access to, no privileges required!
Don't like that? Then PLEASE UPDATE your system ASAP to PackageKit >= 1.3.5 or any fixed distro package. Fixes for this vulnerability should already be available everywhere since today.
You can read more about CVE-2026-41651 on the security researcher's blog:
https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html -
Forgot your root password? No problem! With #PackageKit <= 1.3.4 you can do all the fun root action on any Linux system you have local access to, no privileges required!
Don't like that? Then PLEASE UPDATE your system ASAP to PackageKit >= 1.3.5 or any fixed distro package. Fixes for this vulnerability should already be available everywhere since today.
You can read more about CVE-2026-41651 on the security researcher's blog:
https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html -
Just damn. The coding A-team keeps on pushing the envelope for reverse engineering.
Everything from shaping the graphics stack to fully utilizing the GPU instead of falling back to software rendering, as well as figuring out many other quirks, the team behind #Asahi is a credit to #Linux kernel developers.
One of them even updated #PackageKit to DNF5 for the Asahi Fedora Remix so they could stop packaging twice. Neat!
Progress Report: #Linux 6.19 - Asahi Linux
https://asahilinux.org/2026/02/progress-report-6-19/ -
Just damn. The coding A-team keeps on pushing the envelope for reverse engineering.
Everything from shaping the graphics stack to fully utilizing the GPU instead of falling back to software rendering, as well as figuring out many other quirks, the team behind #Asahi is a credit to #Linux kernel developers.
One of them even updated #PackageKit to DNF5 for the Asahi Fedora Remix so they could stop packaging twice. Neat!
Progress Report: #Linux 6.19 - Asahi Linux
https://asahilinux.org/2026/02/progress-report-6-19/ -
To celebrate the end of the year, I've completed one of the biggest ticket items I had: I've made a brand new #PackageKit backend for Linux distributions using #DNF version 5. github.com/PackageKit/P... If you like this kind of work, please consider sponsoring me! github.com/sponsors/Con...
Initial implementation of the ... -
To celebrate the end of the year, I've completed one of the biggest ticket items I've had in a while: I've made a brand new #PackageKit backend for Linux distributions using #DNF version 5.
https://github.com/PackageKit/PackageKit/pull/931
This has been partly possible thanks to having the time to do it, but I'd like to be able to have time to do more big things like this. If you want that too, consider sponsoring me!
-
To celebrate the end of the year, I've completed one of the biggest ticket items I've had in a while: I've made a brand new #PackageKit backend for Linux distributions using #DNF version 5.
https://github.com/PackageKit/PackageKit/pull/931
This has been partly possible thanks to having the time to do it, but I'd like to be able to have time to do more big things like this. If you want that too, consider sponsoring me!
-
This is how to make the “Install pending software updates” checkbox go away in GNOME
If you’re using GNOME, and when you tell it you want to shut down or reboot your system it pops up a confirmation dialog with an “Install pending software update” checkbox in it, and the checkbox is checked by default, and you want to make that checkbox go away or at least be unchecked by default, then you’ve come to the right place.
There’s no perfect way to do this. Below I talk about two imperfect solutions that are available. If you think there should be an easier way, feel free to weigh in here. The GNOME developers are skeptical that anyone wants or needs this, but maybe if enough people ask for it they will reconsider.
Imperfect solution one: Open the preferences for the GNOME Software app and change “Software Updates” there from “Automatic” to “Manual”. Caveats:
- This may only work on systems, such as Fedora-based systems, where PackageKit uses a separate update cache from the system. On APT-based systems (Debian, Ubuntu, and the like), where it appears that PackageKit uses the same update cache as the underlying APT system (as it should!), then when the updates are downloaded outside of GNOME Software, you may still see the checkbox.
- If there were already updates downloaded before you switched from Automatic to Manual, you will get the checkbox. You need to install those updates (either through GNOME Software or with DNF or APT or whatever) and then refresh the GNOME Software Updates tab to make them go away there.
- If you check for updates in the GNOME Software app manually and then click the Download button, you will probably get the checkbox the next time you try to shut down or restart.
Imperfect solution two: Create the file
/etc/polkit-1/rules.d/99-disable-offline-update.rules, owned by user “root” and group “polkitd”, with the following contents:polkit.addRule(function(action, subject) { if ((action.id == "org.freedesktop.packagekit.trigger-offline-update")) { return polkit.Result.NO; } });Caveat: This will disable all attempts to trigger offline updates, not just the checkbox that shows up when you try to shutdown or restart your system. This means, for example, that you won’t be able to trigger “Restart and install…” updates from inside the GNOME Software app either.
#GNOME #PackageKit #Polkit -
This is how to make the “Install pending software updates” checkbox go away in GNOME
If you’re using GNOME, and when you tell it you want to shut down or reboot your system it pops up a confirmation dialog with an “Install pending software update” checkbox in it, and the checkbox is checked by default, and you want to make that checkbox go away or at least be unchecked by default, then you’ve come to the right place.
There’s no perfect way to do this. Below I talk about two imperfect solutions that are available. If you think there should be an easier way, feel free to weigh in here. The GNOME developers are skeptical that anyone wants or needs this, but maybe if enough people ask for it they will reconsider.
Imperfect solution one: Open the preferences for the GNOME Software app and change “Software Updates” there from “Automatic” to “Manual”. Caveats:
- This may only work on systems, such as Fedora-based systems, where PackageKit uses a separate update cache from the system. On APT-based systems (Debian, Ubuntu, and the like), where it appears that PackageKit uses the same update cache as the underlying APT system (as it should!), then when the updates are downloaded outside of GNOME Software, you may still see the checkbox.
- If there were already updates downloaded before you switched from Automatic to Manual, you will get the checkbox. You need to install those updates (either through GNOME Software or with DNF or APT or whatever) and then refresh the GNOME Software Updates tab to make them go away there.
- If you check for updates in the GNOME Software app manually and then click the Download button, you will probably get the checkbox the next time you try to shut down or restart.
Imperfect solution two: Create the file
/etc/polkit-1/rules.d/99-disable-offline-update.rules, owned by user “root” and group “polkitd”, with the following contents:polkit.addRule(function(action, subject) { if ((action.id == "org.freedesktop.packagekit.trigger-offline-update")) { return polkit.Result.NO; } });Caveat: This will disable all attempts to trigger offline updates, not just the checkbox that shows up when you try to shutdown or restart your system. This means, for example, that you won’t be able to trigger “Restart and install…” updates from inside the GNOME Software app either.
#GNOME #PackageKit #Polkit -
🤔 Do you use #KDEPlasma6?
🤔 Are you on #Ubuntu 25.10?
😠 Tired of #PackageKit asking you to authenticate every hour or so while #Discover is running?
I know that AI is a bad-word around here, but I asked #ChatGPT and its first suggestion worked on the first try.
Just saying.
https://chatgpt.com/share/6930dd33-d3cc-8008-b707-c1ba3af43aa4 -
Something changed with #Kubuntu 25.10 over the past week. Now all of a sudden I'm getting #prompted for my #sudo #password every time #PackageKit runs to update package sources (which is several times a day)!
Fortunately, you can create a custom #PolKit #rule to let it run without prompting you!sudo nano /etc/polkit-1/rules.d/10-allow-packagekit-refresh.rulespolkit.addRule(function(action, subject) { if (action.id == "org.freedesktop.packagekit.system-sources-refresh" && subject.isInGroup("sudo")) { return polkit.Result.YES; } });
And that seems to work.
#Linux #Ubuntu #KDE #KDE6 #Plasma6 #KDEPlasma6 #Discover #updates -
Joey Riches has been working on packagekit integration for moss so that we can have a nicer GUI experience for package installation of our stone based packages.
A short summary of his progress:
- Generated rust bindings for packagekit
- Wrote the moss backend for packagekit and implemented all functionality that moss supports
- Gnome software can list, install & update packages - working on getting a appstream catalog hosted for full functionalityTODO:
- Figure out C/rust interop story to minimise usage of unsafe
- Get support for misc. items implemented in moss such as repo origin of packages
- Get progress bar callback support in
- Implement support for remaining more niche packagekit filters e.g. newest, devel, basename, etc
- Figure out build system: integrate rust bindings & our backend upstream or develop it downstream for now?It sometimes needs saying that we are fleshing out our distro from scratch, which means we are having to build new integrations like this from scratch. This is a good thing as we have been finding opportunities for optimisation across our code base, but it does require time.
-
Joey Riches has been working on packagekit integration for moss so that we can have a nicer GUI experience for package installation of our stone based packages.
A short summary of his progress:
- Generated rust bindings for packagekit
- Wrote the moss backend for packagekit and implemented all functionality that moss supports
- Gnome software can list, install & update packages - working on getting a appstream catalog hosted for full functionalityTODO:
- Figure out C/rust interop story to minimise usage of unsafe
- Get support for misc. items implemented in moss such as repo origin of packages
- Get progress bar callback support in
- Implement support for remaining more niche packagekit filters e.g. newest, devel, basename, etc
- Figure out build system: integrate rust bindings & our backend upstream or develop it downstream for now?It sometimes needs saying that we are fleshing out our distro from scratch, which means we are having to build new integrations like this from scratch. This is a good thing as we have been finding opportunities for optimisation across our code base, but it does require time.
-
Let's just face facts, folks.
#KDE Discover is faster than #GNOME software, but #COSMIC Store has them beat - and partly to blame is #PackageKit.
There's a point where "seperation of concerns" goes awry, and this abstraction of package managers is imho one such example.
This is ofc a #UX issue. If we compare with say #AppStore or #PlayStore or #MicrosoftStore even, we can sort of feel our way to how each are sluggish in their own way.
But some of those GNOME Software loading times? Goddamn.
-
Let's just face facts, folks.
#KDE Discover is faster than #GNOME software, but #COSMIC Store has them beat - and partly to blame is #PackageKit.
There's a point where "seperation of concerns" goes awry, and this abstraction of package managers is imho one such example.
This is ofc a #UX issue. If we compare with say #AppStore or #PlayStore or #MicrosoftStore even, we can sort of feel our way to how each are sluggish in their own way.
But some of those GNOME Software loading times? Goddamn.
-
I am today years old to know that GNOME software is powered by PackageKit that is run in a way that even bypass local PackageKit configuration...
-
I am today years old to know that GNOME software is powered by PackageKit that is run in a way that even bypass local PackageKit configuration...
-
I am very honored to be part of the first Sovereign Tech Fellowship program!
This will directly support my work on #FreeDesktop, #AppStream and #PackageKit, so expect a lot more changes faster, and also way faster patch reviews.
This is also the first time ever that I have dedicated time to work on fd.o, and I am excited about the possibilities! You can expect blog posts about it in future 😄You can read more about the amazing program and the other fellows here:
https://www.sovereign.tech/news/meet-the-sovereign-tech-fellows -
I am very honored to be part of the first Sovereign Tech Fellowship program!
This will directly support my work on #FreeDesktop, #AppStream and #PackageKit, so expect a lot more changes faster, and also way faster patch reviews.
This is also the first time ever that I have dedicated time to work on fd.o, and I am excited about the possibilities! You can expect blog posts about it in future 😄You can read more about the amazing program and the other fellows here:
https://www.sovereign.tech/news/meet-the-sovereign-tech-fellows -
This is something Linux kinda gets right. One-click install and done, especially with Flatpak. Though, apparently PackageKit, which is meant to abstract the package manager stuff, is dead. Anyone in the know, do you know what's replacing it? Curious.
-
#PackageKit works wonderfully.
https://gist.github.com/AliveDevil/646a63b88fedca0ebfdf2b82ef0fab34
Just hangs there and doesn't show anything.
With --backends packagekit this works, with --backends flatpak this hangs.