Maple Grove Report

Maple Grove Report

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.


12-year-old Pack2TheRoot bug lets Linux users gain root privileges

Pierluigi Paganini
April 24, 2026

‘Pack2TheRoot’ flaw lets local Linux users gain root via PackageKit. CVE-2026-41651 (8.8) has existed for nearly 12 years.

The Pack2TheRoot flaw, tracked as CVE-2026-41651, lets unprivileged users install or remove system packages without authorization, potentially gaining full root access.

The vulnerability is rated high severity, CVSS score of 8.8, and has existed for nearly 12 years.

Discovered by Deutsche Telekom’s Red Team, it stems from PackageKit allowing commands like “pkcon install” to run without a password on some systems. Researchers used AI (Claude Opus) to explore the issue, confirmed it manually, and responsibly disclosed it to maintainers, who validated the flaw.

“Today we publicly disclose a high-severity vulnerability (CVSS 3.1: 8.8) – in coordination with distro maintainers – that affects multiple Linux distributions in their default installations. The Pack2TheRoot vulnerability can be exploited by any local unprivileged user to obtain root access on a vulnerable system.” reads the advisory published by Deutsche Telekom. “The vulnerability lies in the PackageKit daemon, a cross-distro package management abstraction layer.

Details of the Pack2TheRoot flaw were disclosed alongside a fix in PackageKit 1.3.5, though exploit code was withheld to allow patching. Deutsche Telekom researchers found that PackageKit could run commands like “pkcon install” without authentication in some cases on Fedora, enabling package installation. The researchers used the Claude Opus AI tool to explore this behavior further and identified the vulnerability as CVE-2026-41651.

All PackageKit versions from 1.0.2 to 1.3.4 are vulnerable, affecting many Linux distributions for over 12 years. Tested systems include Ubuntu, Debian, Fedora, and Rocky Linux, and others using PackageKit may also be at risk, including servers with Cockpit. The issue is fixed in version 1.3.5, with patches released on April 22, 2026.

Technical details of the vulnerability are not yet disclosed and will be shared later. Researchers have developed a reliable proof-of-concept that allows an unprivileged local user to gain root code execution on default Linux systems. However, the PoC code has not been released publicly to prevent abuse while patches are being deployed.

To check if you’re vulnerable, verify if PackageKit is installed using dpkg or rpm, as it may run on demand via D-Bus. Then check if the service is active with systemctl or monitoring tools like pkmon/pkgcli. If active and unpatched, your system may be at risk. Although fixed in version 1.3.5, many distributions have released patched versions separately, so updating via your distro is essential.

You can use the following commands to check whether a vulnerable version of PackageKit is installed on your system:

dpkg -l | grep -i packagekit
rpm -qa | grep -i packagekit

To verify if the PackageKit daemon is active, run systemctl status packagekit or pkmon. If the service is loaded or running, your system may be at risk if it has not been patched.

Researchers released Indicators of compromise (IOCs) for this flaw.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Pack2TheRoot)







Source link


Home Depot Spring Black Friday

Home Depot/ZDNET

Follow ZDNET: Add us as a preferred source on Google.


Spring is here, and Home Depot’s annual Spring Black Friday sale is back this week, starting Thursday. It’s one of the retailer’s biggest seasonal sales, with deals of up to 40% off on mulch, grills, outdoor power equipment, appliances, patio furniture, and more for your home and garden.

Also: Best robot mowers of 2026: From Husqvarna to Segway, here are the top performers

Home Depot has said to expect deals from top brands like DeWalt, Milwaukee, LG, Weber, Traeger, and Whirlpool, among others. ZDNET’s deals experts are here using our extensive hands-on tech experience and sale-tracking skills to break down everything you need to know about the Home Depot sale and how to find the best deals this spring.

When does the Home Depot Spring Black Friday sale start?

The Home Depot Spring Black Friday sale starts on Thursday, April 9. It runs through Wednesday, April 22. You can shop both in-store and online. 

When does the Home Depot spring sale end?

The final day of the Home Depot Spring Black Friday sale is Wednesday, April 22.

What are the top deals during Home Depot’s Spring Black Friday sale? 

Home Depot will have deals on lawnmowers, grills, power tools, patio furniture, mulch and gardening supplies, and much more, from top brands including DeWalt, Nexgrill, Milwaukee, Ryobi, Weber, Trex, Rigid, Traeger, Leviton, GE Appliances, Samsung, LG, Whirlpool, and Frigidaire. Home Depot shared the following deal categories: 

  • Lawn & garden: Outdoor power equipment, plants, flowers, mulch, weed, and grass killer 

  • Backyard hosting: Patio furniture, patio dining sets, grills, composite decking

  • Pro: Bulk price savings and essentials for the pros, including tools, pipe, water heaters, and paint tools

  • Home upgrades: Paint, faucets, flooring, toilets, fans, fencing, cleaning supplies, appliances (refrigerator, oven, dishwasher, washer & dryer)

  • Storage & organizational solutions: Tool bags, storage shelves, boxes with handles

My well used DeWalt cordless drill

Adrian Kingsley-Hughes/ZDNET

What is the Home Depot Spring Black Friday sale?

Home Depot’s Spring Black Friday sale is the retailer’s annual spring sale, where you’ll find discounts of up to 40% on spring essentials, including grills, lawnmowers, power tools, patio furniture, plants, gardening supplies, and more. The spring sale has been happening for over a decade.

When does mulch go on sale at Home Depot?

Mulch, garden soil, plants, and other gardening supplies will go on sale on Thursday, April 9, as the Home Depot Spring Black Friday sale begins.

How long is the Home Depot Spring Black Friday sale?

The Home Depot Spring Black Friday sale will take place from Thursday, April 9, through Wednesday, April 22, 2026.

Does Home Depot price match?

Yes, Home Depot does price match competitors, including Lowe’s, Amazon, Target, and local stores. To get a price match, ensure the item you want is identical (same brand, model, and size) to the one sold at Home Depot, and is in stock and able to be shipped to your location. Bring the ad, printout, or website link displaying the competitor’s lower price to the cashier at checkout. 

You can also price match when shopping online by contacting Home Depot’s Customer Solutions team by clicking the Live Chat link to the right or calling 1-800-430-3376. You’ll provide the associate with the SKU or Internet number from homedepot.com, the competitor’s name, and the competitor’s identifier for the product.

Why trust ZDNET to help you shop?

As members of the ZDNET staff, we only write about deals that we would want to buy — devices and products we desire, need, or would recommend. We look for deals where products are at least 20% off (or are hardly ever on sale), using established price-comparison tools and trackers to determine whether the deal is on sale and how often it drops.

We also look over customer reviews to see what matters to real people who already own and use the products in the deals we recommend. These recommendations may also be based on our testing, along with extensive research and comparison shopping. The goal is to deliver the most accurate advice to help you shop smarter. ZDNET offers 33 years of experience, 30 hands-on product reviewers, and 10,000 square feet of lab space to ensure we bring you the best tech.

Plus, in 2026, ZDNET refined its approach to deals, developing a measurable system for sharing savings with readers like you. Our editor’s deal rating badges are affixed to most of our deal content, making it easy to interpret our expertise to help you make the best purchase decision. 

Also: How we rate deals at ZDNET in 2026

Looking for more shopping tips? Check out the 3 money-saving tricks I use every time I shop online – and why you should too.





Source link

Recent Reviews