‘Pack2TheRoot’ local Linux root bug
- Security researchers disclosed a PackageKit vulnerability nicknamed “Pack2TheRoot” that lets a local Linux user install or remove packages and escalate to root privileges. - The flaw specifically targets PackageKit, a common package-management helper used on many Linux desktops and servers. - The bug highlights that control-plane utilities like package managers deserve production-grade threat modeling and monitoring. (bleepingcomputer.com)