High severity8.2NVD Advisory· Published Nov 7, 2020· Updated Jun 17, 2026
CVE-2020-16122
CVE-2020-16122
Description
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:packagekit_project:packagekit:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:packagekit_project:packagekit:-:*:*:*:*:*:*:*
- (no CPE)
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- PackageKit/packagekitv5Range: 1.1.13-2ubuntu
Patches
Vulnerability mechanics
References
1- bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1882098nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.