{"id":"CVE-2026-19816","summary":"PackageKit: dnf5 backend ignores SIMULATE on RepoRemove","details":"A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.","aliases":["GHSA-g5gf-h68q-gxc8"],"modified":"2026-09-17T08:15:55.401552Z","published":"2026-09-14T20:05:00.169Z","database_specific":{"cna_assigner":"fedora","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19816.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://bodhi.fedoraproject.org/updates/?packages=PackageKit"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19816.json"},{"type":"ADVISORY","url":"https://github.com/PackageKit/PackageKit/security/advisories/GHSA-g5gf-h68q-gxc8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19816"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515940"},{"type":"FIX","url":"https://github.com/PackageKit/PackageKit/commit/33be77b3ecd3b566ca117358dc18c58c964e627b"},{"type":"PACKAGE","url":"https://github.com/PackageKit/PackageKit"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/packagekit/packagekit","events":[{"introduced":"aa8e994711b1debd485e8d2e06f5ff4ac3494a65"},{"fixed":"33be77b3ecd3b566ca117358dc18c58c964e627b"}],"database_specific":{"extracted_events":[{"introduced":"1.3.4"},{"fixed":"1.4.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.3.6","v1.3.5","v1.3.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19816.json","vanir_signatures_modified":"2026-09-17T08:15:55Z","vanir_signatures":[{"source":"https://github.com/packagekit/packagekit/commit/33be77b3ecd3b566ca117358dc18c58c964e627b","target":{"file":"backends/dnf5/dnf5-backend-thread.cpp","function":"dnf5_transaction_thread"},"deprecated":false,"digest":{"function_hash":"270461123028998288870474421320959343379","length":7840},"id":"CVE-2026-19816-2848a412","signature_type":"Function","signature_version":"v1"},{"target":{"file":"backends/dnf5/dnf5-backend-thread.cpp"},"deprecated":false,"digest":{"line_hashes":["171237454910942151134272633908483188324","208416502006613427203470661593680397330","83666962922781040001010884852185290866","90932504323604005399669864871396355657","335388204447370313008434221149743623782","30164295831447238112819618187149215760","254045841424264766247508436798178675801","324968928179143455818430726602944587431","222440860946810283281804467182168602197","100143797007324273795077498666700964366","234143384742276132942246197973849405087","77695068122427647746603121581344597807","184624696468649856029688835192856030239","134852853111390111794371945387457642293","328174982379127202173274759680312670060","218853539589914721521657881344217322481","176401807287483131812586819056612135187","338694414875352571591346238338062360946","288450575237033810204090069390314985777","274450393798501509621806252133888604656","17703789391370130476328287686713731120","338848011217005578756057327466152662828","288450575237033810204090069390314985777","274450393798501509621806252133888604656","17703789391370130476328287686713731120","19326727229521545158549323745366388388","149023440095359658286255476541907046350","297009935371518550487640813362384143434","126773478233768570645783975351830765637","293575060895465527674987426541805731749","110135528444295677486946581880276817356","16164951993528750913922288026426937592","326220248040233455152114439103971540684","163293596709540279957772978136503361131","86306514190786929730290436894438998373","288756151529357593617608017355081619103","110962691690873480608723074962369142902","249618183166741635444167739460125473251","138288281903682535794609863300078133866","302520314919158518878094909828121814020","87088447637569863349722039763094747787","74928828692898101291055364743242867150","59633921447959060914154758107474561051","211253111680599717396393146714783760716","198608529642377323803428883777543760696","79007256589712313630067021520054716170","51026617011380588040406385122297507866","278359482300257932943327063279284818256","236402903464329132328598708708093495064","24905583221533528761884902673305787189","29854917536281460153902166376024162984","250591168648629658674386286999368127372","161657740799757150516000513883657973027","98662990057714094859427379470999646918","24494627877179952498992217435857170738","266718837321299002518978140756310204159","330255126197451653313412075739557392970","147976990335538555198451732370584810690"],"threshold":0.9},"id":"CVE-2026-19816-36053575","signature_type":"Line","signature_version":"v1","source":"https://github.com/packagekit/packagekit/commit/33be77b3ecd3b566ca117358dc18c58c964e627b"},{"id":"CVE-2026-19816-629cd7d0","signature_type":"Function","signature_version":"v1","source":"https://github.com/packagekit/packagekit/commit/33be77b3ecd3b566ca117358dc18c58c964e627b","target":{"file":"backends/dnf5/dnf5-backend-thread.cpp","function":"dnf5_repo_thread"},"deprecated":false,"digest":{"function_hash":"307478140725154941899769849548852032538","length":5338}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}