Impact
A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry‑run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
Affected Systems
Affected systems include Fedora and Red Hat Enterprise Linux 10, 6, 7, 8, and 9 running PackageKit with the dnf5 backend.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, indicating a high severity. EPSS data indicates a low exploitation probability of < 1% (0.00143), and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local and does not require privileged access prior to execution, so exploit this by invoking package removal commands. Given the lack of an official patch or workaround, the risk remains significant for affected installations.
OpenCVE Enrichment