Debian Package Tracker
Register | Log in
Subscribe

packagekit

Provides a package management service

Choose email to subscribe with

general
  • source: packagekit (main)
  • version: 1.4.0-1
  • maintainer: Matthias Klumpp (DMD)
  • uploaders: Julian Andres Klode [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.2.2-2
  • o-o-sec: 1.2.2-2+deb11u1
  • oldstable: 1.2.6-5+deb12u1
  • old-sec: 1.2.6-5+deb12u1
  • stable: 1.3.1-1+deb13u1
  • stable-sec: 1.3.1-1+deb13u1
  • testing: 1.4.0-1
  • unstable: 1.4.0-1
versioned links
  • 1.2.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.2-2+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.6-5+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.3.1-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gir1.2-packagekitglib-1.0 (1 bugs: 0, 1, 0, 0)
  • gstreamer1.0-packagekit
  • libpackagekit-glib2-18
  • libpackagekit-glib2-dev
  • packagekit (19 bugs: 0, 18, 1, 0)
  • packagekit-command-not-found
  • packagekit-docs
  • packagekit-gtk3-module
action needed
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-19816: A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
1 issue postponed or untriaged:
  • CVE-2026-10294: (postponed; to be fixed through a stable update) A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Created: 2026-09-10 Last update: 2026-09-15 06:30
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • gir1.2-packagekitglib-1.0 could be marked Multi-Arch: same
Created: 2026-06-21 Last update: 2026-09-15 22:03
Depends on packages which need a new maintainer normal
The packages that packagekit depends on which need a new maintainer are:
  • docbook-xsl (#802370)
    • Build-Depends: docbook-xsl-ns
Created: 2026-01-29 Last update: 2026-09-15 21:00
lintian reports 9 warnings normal
Lintian reports 9 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-11 Last update: 2026-09-11 19:30
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-10294: (needs triaging) A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argument frontend-socket leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
  • CVE-2026-19816: (needs triaging) A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-06-02 Last update: 2026-09-15 06:30
news
[rss feed]
  • [2026-09-15] packagekit 1.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-09] Accepted packagekit 1.4.0-1 (source) into unstable (Matthias Klumpp)
  • [2026-06-22] packagekit 1.3.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-16] Accepted packagekit 1.3.6-1 (source) into unstable (Matthias Klumpp)
  • [2026-05-02] Accepted packagekit 1.2.6-5+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-25] Accepted packagekit 1.3.1-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-24] packagekit 1.3.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-22] Accepted packagekit 1.3.1-1+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-22] Accepted packagekit 1.2.6-5+deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-04-22] Accepted packagekit 1.3.5-1 (source) into unstable (Matthias Klumpp)
  • [2026-04-22] Accepted packagekit 1.2.2-2+deb11u1 (source) into oldoldstable-security (Thorsten Alteholz)
  • [2026-02-07] packagekit 1.3.4-3 MIGRATED to testing (Debian testing watch)
  • [2026-02-01] Accepted packagekit 1.3.4-3 (source) into unstable (Jeremy Bícha)
  • [2026-01-28] Accepted packagekit 1.3.4-1 (source) into unstable (Matthias Klumpp)
  • [2025-11-30] packagekit 1.3.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-24] Accepted packagekit 1.3.3-1 (source) into unstable (Matthias Klumpp)
  • [2025-10-08] packagekit 1.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-02] Accepted packagekit 1.3.2-1 (source) into unstable (Matthias Klumpp)
  • [2025-05-03] packagekit 1.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-22] Accepted packagekit 1.3.1-1 (source) into unstable (Matthias Klumpp)
  • [2025-02-22] packagekit 1.3.0-3 MIGRATED to testing (Debian testing watch)
  • [2025-02-17] Accepted packagekit 1.3.0-3 (source) into unstable (Julian Andres Klode)
  • [2024-11-14] packagekit 1.3.0-2 MIGRATED to testing (Debian testing watch)
  • [2024-11-08] Accepted packagekit 1.3.0-2 (source) into unstable (Alessandro Astone) (signed by: Jeremy Bicha)
  • [2024-06-22] packagekit 1.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-16] Accepted packagekit 1.3.0-1 (source) into unstable (Matthias Klumpp)
  • [2024-02-26] packagekit 1.2.8-2 MIGRATED to testing (Debian testing watch)
  • [2024-02-20] Accepted packagekit 1.2.8-2 (source) into unstable (Matthias Klumpp)
  • [2023-11-14] packagekit 1.2.8-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-08] Accepted packagekit 1.2.8-1 (source) into unstable (Matthias Klumpp)
  • 1
  • 2
bugs [bug history graph]
  • all: 25
  • RC: 0
  • I&N: 21
  • M&W: 4
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 9)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 56)
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.3.6-1ubuntu1
  • 33 bugs
  • patches for 1.3.6-1ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing