PackageKit vulnerability
Published: Wed, 29 Apr 2026 08:59
Summary
PackageKit could be made to install packages as the administrator.
Details
USN-8195-1 fixed a vulnerability in PackageKit. This update provides the corresponding fix to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that PackageKit incorrectly handled certain transactions. A local attacker could use this issue to install arbitrary packages as root, possibly resulting in privilege escalation.
Recommended actions per Ubuntu release
StackPatch playbook auto-generated per release codename and per affected package.
Ubuntu bionic
packagekit→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
gir1.2-packagekitglib-1.0→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gir1.2-packagekitglib-1.0
Most apt upgrades restart their service automatically. needrestart lists anything else.
gstreamer1.0-packagekit→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gstreamer1.0-packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
libpackagekit-glib2-18→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libpackagekit-glib2-18
Most apt upgrades restart their service automatically. needrestart lists anything else.
libpackagekit-glib2-dev→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libpackagekit-glib2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-command-not-found→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-command-not-found
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-docs→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-docs
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-gtk3-module→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-gtk3-module
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-tools→1.1.9-1ubuntu2.18.04.6+esm1apt_upgradeStandard apt upgrade. Install 1.1.9-1ubuntu2.18.04.6+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-tools
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu focal
packagekit→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
gir1.2-packagekitglib-1.0→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gir1.2-packagekitglib-1.0
Most apt upgrades restart their service automatically. needrestart lists anything else.
gstreamer1.0-packagekit→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gstreamer1.0-packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
libpackagekit-glib2-18→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libpackagekit-glib2-18
Most apt upgrades restart their service automatically. needrestart lists anything else.
libpackagekit-glib2-dev→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libpackagekit-glib2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-command-not-found→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-command-not-found
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-docs→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-docs
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-gtk3-module→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-gtk3-module
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-tools→1.1.13-2ubuntu1.1+esm1apt_upgradeStandard apt upgrade. Install 1.1.13-2ubuntu1.1+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-tools
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu xenial
packagekit→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
gir1.2-packagekitglib-1.0→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gir1.2-packagekitglib-1.0
Most apt upgrades restart their service automatically. needrestart lists anything else.
gstreamer1.0-packagekit→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gstreamer1.0-packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
libpackagekit-glib2-16→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libpackagekit-glib2-16
Most apt upgrades restart their service automatically. needrestart lists anything else.
libpackagekit-glib2-dev→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y libpackagekit-glib2-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-backend-aptcc→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-backend-aptcc
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-backend-smart→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-backend-smart
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-docs→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-docs
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-gtk3-module→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-gtk3-module
Most apt upgrades restart their service automatically. needrestart lists anything else.
packagekit-tools→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y packagekit-tools
Most apt upgrades restart their service automatically. needrestart lists anything else.
python3-packagekit→0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1apt_upgradeStandard apt upgrade. Install 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y python3-packagekit
Most apt upgrades restart their service automatically. needrestart lists anything else.
Are YOU affected by USN-8195-3?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8195-3 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
StackPatch runs this match against YOUR installed packages every hour
Free 1-server / $99 lifetime founder seat (50 only) / $19+/mo monthly. Indie pricing.