- What: Security update for PackageKit in Ubuntu
- Impact: Fixes a vulnerability that could allow local privilege escalation
Ubuntu Security Notices USN-8195-3 USN-8195-3: PackageKit vulnerability Publication date 29 April 2026 Overview PackageKit could be made to install packages as the administrator. Releases 20.04 LTS 18.04 LTS 16.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages packagekit - Provides a package management service Details USN-8195-1 fixed a vulnerability in PackageKit. This update provides the corresponding fix to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that PackageKit incorrectly handled certain transactions. A local attacker could use this issue to install arbitrary packages as root, possibly resulting in privilege escalation. USN-8195-1 fixed a vulnerability in PackageKit. This update provides the corresponding fix to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that PackageKit incorrectly handled certain transactions. A local attacker could use this issue to install arbitrary packages as root, possibly resulting in privilege escalation. Update instructions After a standard system update you need to reboot your computer to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 20.04 LTS focal packagekit – 1.1.13-2ubuntu1.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . 18.04 LTS bionic packagekit – 1.1.9-1ubuntu2.18.04.6+esm1 Ubuntu Pro Fix available with Ubuntu Pro . 16.04 LTS xenial packagekit – 0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1 Ubuntu Pro Fix available with Ubuntu Pro . Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-41651 CVE-2026-41651