Forgot your root password? No problem! With #PackageKit <= 1.3.4 you can do all the fun root action on any Linux system you have local access to, no privileges required!
Don't like that "feature"? Then PLEASE UPDATE your system ASAP to PackageKit >= 1.3.5 or any fixed distro package! 1/3
Thanks to the Red Team of Deutsche Telekom Security GmbH for finding and reporting this issue, and all the package maintainers who worked to ensure fixes are ready and shipped today.
If you are using Arch, Debian, Ubuntu or Fedora, you should already have updates waiting. 3/3
Fixes for this vulnerability should already be available everywhere since today.
You can read more about CVE-2026-41651 on the security researcher's blog: github.security.telekom.com/2026/04/pack... 2/3
#pack2theroot #osssecurity #freedesktop
I am very honored to be part of the first Sovereign Tech Fellowship program!
This will directly support my work on #FreeDesktop, #AppStream and #PackageKit, so expect a lot more changes faster, and also way faster patch reviews. Also check out the amazing program and the other fellows!
Open source maintainer and PhD candidate @mklu.bsky.social first got curious about Linux as a teenager with a very slow internet connection but big passion for computer systems. That curiosity sparked a journey into open source that continues to this day.
In our latest blog post, we take you inside the event with a recap of the highlights ➡️
www.sovereign.tech/news/who-wil...
@icing.bsky.social @hugovk.dev @mklu.bsky.social
Zu Open Source Week der Vereinten Nationen bringen wir eine Delegation von 12 Open-Source-Expert*innen zusammen, deren Arbeit die digitale Infrastruktur, auf die wir alle angewiesen sind, aufrechterhält. Ihre Teilnahme bringt wichtige...
#UNOpenSourceWeek #maintainathon #MaintainerSpotlight 1/3
Matthias Klumpp
In case you missed it last week, here’s the first of a series of in-depth interviews from the first cohort of the Sovereign Tech Fellowship.
Open source maintainer Sarah Hoffmann loves to discover beautiful places IRL – and in code: www.sovereign.tech/news/meet-sa...
#MaintainerSpotlight