{"id":38886,"date":"2026-04-24T09:50:50","date_gmt":"2026-04-24T01:50:50","guid":{"rendered":"https:\/\/www.deepin.org\/?p=38886"},"modified":"2026-04-24T10:03:06","modified_gmt":"2026-04-24T02:03:06","slug":"deepin-25-1-upgrade-announcement-260423","status":"publish","type":"post","link":"https:\/\/www.deepin.org\/zh\/deepin-25-1-upgrade-announcement-260423\/","title":{"rendered":"\u5b89\u5168\u66f4\u65b0\u3001\u5efa\u8bae\u5347\u7ea7 | deepin 25.1 \u6b63\u5f0f\u7248\u66f4\u65b0\u516c\u544a"},"content":{"rendered":"<img loading=\"lazy\" class=\"alignnone size-full wp-image-38887\" src=\"https:\/\/www.deepin.org\/wp-content\/uploads\/2026\/04\/260423_\u526f\u672c.png\" alt=\"\" width=\"900\" height=\"383\" srcset=\"https:\/\/www.deepin.org\/wp-content\/uploads\/2026\/04\/260423_\u526f\u672c.png 900w, https:\/\/www.deepin.org\/wp-content\/uploads\/2026\/04\/260423_\u526f\u672c-300x128.png 300w, https:\/\/www.deepin.org\/wp-content\/uploads\/2026\/04\/260423_\u526f\u672c-150x64.png 150w, https:\/\/www.deepin.org\/wp-content\/uploads\/2026\/04\/260423_\u526f\u672c-768x327.png 768w, https:\/\/www.deepin.org\/wp-content\/uploads\/2026\/04\/260423_\u526f\u672c-24x10.png 24w, https:\/\/www.deepin.org\/wp-content\/uploads\/2026\/04\/260423_\u526f\u672c-36x15.png 36w, https:\/\/www.deepin.org\/wp-content\/uploads\/2026\/04\/260423_\u526f\u672c-48x20.png 48w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/p>\n<p data-pm-slice=\"0 0 []\"><span data-font-family=\"default\">\ud83d\udd14\u00a0\u4eb2\u7231\u7684 deepin \u7528\u6237\u4e0e\u793e\u533a\u4f19\u4f34\u4eec\uff0c<\/span><\/p>\n<p data-pm-slice=\"0 0 []\"><span data-font-family=\"default\">deepin 25.1 \u66f4\u65b0\u6765\u5566\uff01\u672c\u6b21\u66f4\u65b0\u6d89\u53ca\u6700\u65b0\u201cPack2TheRoot\u201d \u9ad8\u5371\u6f0f\u6d1e\u7d27\u6025\u4fee\u590d\uff0c\u540c\u65f6\u9488\u5bf9\u8fd1\u671f\u5347\u7ea7\u7528\u6237\u97f3\u9891\u8bbe\u5907\u4e22\u5931\u95ee\u9898\u8fdb\u884c\u4e86\u4f18\u5316\uff0c\u5f3a\u70c8\u5efa\u8bae\u5927\u5bb6\u7b2c\u4e00\u65f6\u95f4\u66f4\u65b0\u5347\u7ea7\u3002<\/span><\/p>\n<p>&nbsp;<\/p>\n<section data-pm-slice=\"0 0 []\">\n<section>\n<section>\n<section>\n<section>\n<section>\n<section>\n<section>\n<section>\n<section>\n<h1><strong>01 2026\u5e744\u670823\u65e5 \u66f4\u65b0\u8be6\u60c5<\/strong><\/h1>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<ul class=\"list-paddingleft-1\">\n<li>\u4fee\u590d\u90e8\u5206\u7528\u6237\u97f3\u9891\u8bbe\u5907\u4e22\u5931\u95ee\u9898\uff1b<\/li>\n<li>\u4fee\u6539\u79fb\u9664\u90e8\u5206\u5931\u6548\u667a\u80fd\u955c\u50cf\u6e90\uff0c\u4fee\u590d\u90e8\u5206\u7528\u6237\u56e0IP\u88ab\u7981\u6b62\u5bfc\u81f4\u7684\u66f4\u65b0\u5931\u8d25\u95ee\u9898\uff1b<\/li>\n<li>\u4fee\u590d\u90e8\u5206\u5df2\u77e5CVE\u5b89\u5168\u6f0f\u6d1e\uff08\u542b\u201cPack2TheRoot\u201d \u9ad8\u5371\u6f0f\u6d1e\uff09\uff0c\u63d0\u5347\u7cfb\u7edf\u5b89\u5168\u6027\u3002<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<section data-pm-slice=\"0 0 []\">\n<h2><strong>\u5173\u4e8e\u201cPack2TheRoot\u201d \u9ad8\u5371\u6f0f\u6d1e\u7d27\u6025\u4fee\u590d\u7684\u8bf4\u660e<\/strong><\/h2>\n<section>Deutsche Telekom\u2019s Red Team \u7684\u5b89\u5168\u7814\u7a76\u5458\u8fd1\u671f\u5728 PackageKit \u4e2d\u53d1\u73b0\u4e86\u4e00\u4e2a Time-of-check Time-of-use (TOCTOU) \u6f0f\u6d1e\u3002<\/section>\n<p>\u8be5\u6f0f\u6d1e\u53ef\u4ee5\u4f7f\u5f97\u975e\u7279\u6743\u7684\u653b\u51fb\u8005\u53ef\u4ee5\u5728\u672a\u7ecf\u6388\u6743\u4e0b\u8fdb\u884c\u5b89\u88c5\u6216\u79fb\u9664\u8f6f\u4ef6\u5305\uff0c\u8fdb\u800c\u53ef\u4ee5\u83b7\u53d6\u5230 root \u6743\u9650\uff0c\u6216\u8fdb\u884c\u5176\u4ed6\u64cd\u4f5c\u3002<\/p>\n<\/section>\n<p><strong>\u6f0f\u6d1e\u7f16\u53f7\uff1aCVE-2026-41651 \/ GHSA-f55j-vvr9-69xv<\/strong><\/p>\n<p>&nbsp;<\/p>\n<h2><strong>\u6211\u662f\u5426\u53d7\u5f71\u54cd\uff1f<\/strong><\/h2>\n<section><span data-pm-slice=\"0 0 []\">\u6240\u6709\u672a\u66f4\u65b0 deepin 25 \u7684\u7528\u6237\u5747\u53d7\u5f71\u54cd\uff0c\u5efa\u8bae\u7acb\u5373\u66f4\u65b0\u5347\u7ea7\u3002<\/span><\/section>\n<section><span data-pm-slice=\"0 0 []\">\u00a0<\/span><\/section>\n<h2><strong>\u4e34\u65f6\u9632\u8303\u63aa\u65bd<\/strong><\/h2>\n<section><span data-pm-slice=\"0 0 []\">\u6682\u65e0\uff0c\u53ea\u80fd\u901a\u8fc7\u7cfb\u7edf\u66f4\u65b0\u89e3\u51b3\u3002<\/span><\/section>\n<p>&nbsp;<\/p>\n<section><\/section>\n<section><\/section>\n<section><span data-pm-slice=\"0 0 []\">\u00a0<\/span><\/section>\n<section data-pm-slice=\"0 0 []\">\n<section>\n<section>\n<section>\n<section data-pm-slice=\"9 7 [&quot;para&quot;,{&quot;tagName&quot;:&quot;section&quot;,&quot;attributes&quot;:{&quot;style&quot;:&quot;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&quot;,&quot;data-pm-slice&quot;:&quot;0 0 []&quot;},&quot;namespaceURI&quot;:&quot;http:\/\/www.w3.org\/1999\/xhtml&quot;},&quot;para&quot;,{&quot;tagName&quot;:&quot;section&quot;,&quot;attributes&quot;:{&quot;style&quot;:&quot;will-change: transform;box-sizing: border-box;&quot;},&quot;namespaceURI&quot;:&quot;http:\/\/www.w3.org\/1999\/xhtml&quot;},&quot;para&quot;,{&quot;tagName&quot;:&quot;section&quot;,&quot;attributes&quot;:{&quot;style&quot;:&quot;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;&quot;},&quot;namespaceURI&quot;:&quot;http:\/\/www.w3.org\/1999\/xhtml&quot;},&quot;para&quot;,{&quot;tagName&quot;:&quot;section&quot;,&quot;attributes&quot;:{&quot;style&quot;:&quot;display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(245, 248, 251);border-left: 5px solid rgb(30, 105, 206);box-sizing: border-box;&quot;},&quot;namespaceURI&quot;:&quot;http:\/\/www.w3.org\/1999\/xhtml&quot;}]\">\n<section>\n<section>\n<section>\n<section>\n<section>\n<h1><strong>02 \u4fee\u590d\u7248\u672c\u4fe1\u606f<\/strong><\/h1>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<p data-pm-slice=\"0 0 []\">deepin 25 \u5df2\u5728\u672c\u6b21\u66f4\u65b0\u4e2d\u901a\u8fc7\u8865\u4e01\u7684\u65b9\u5f0f\u8fdb\u884c\u4fee\u590d\u3002<\/p>\n<p>\u60a8\u53ef\u4ee5\u901a\u8fc7<\/p>\n<p>dpkg\u00a0-l | grep -i packagekit<\/p>\n<p data-pm-slice=\"0 0 []\">\u6765\u68c0\u67e5\u60a8\u5f53\u524d\u7684\u7248\u672c\u3002<\/p>\n<ul class=\"list-paddingleft-1\">\n<li><strong>\u672a\u4fee\u590d\u7248\u672c\u4e3a\uff1a1.2.8-2deepin1 \u00a0\u53ca\u66f4\u4f4e<\/strong><\/li>\n<li><strong>\u4fee\u590d\u7248\u672c\u4e3a\uff1a1.2.8-2deepin2\u00a0<\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<section data-pm-slice=\"0 0 []\">\n<section>\n<section>\n<section>\n<section data-pm-slice=\"9 7 [&quot;para&quot;,{&quot;tagName&quot;:&quot;section&quot;,&quot;attributes&quot;:{&quot;style&quot;:&quot;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&quot;,&quot;data-pm-slice&quot;:&quot;0 0 []&quot;},&quot;namespaceURI&quot;:&quot;http:\/\/www.w3.org\/1999\/xhtml&quot;},&quot;para&quot;,{&quot;tagName&quot;:&quot;section&quot;,&quot;attributes&quot;:{&quot;style&quot;:&quot;will-change: transform;box-sizing: border-box;&quot;},&quot;namespaceURI&quot;:&quot;http:\/\/www.w3.org\/1999\/xhtml&quot;},&quot;para&quot;,{&quot;tagName&quot;:&quot;section&quot;,&quot;attributes&quot;:{&quot;style&quot;:&quot;text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 10px 0px;box-sizing: border-box;&quot;},&quot;namespaceURI&quot;:&quot;http:\/\/www.w3.org\/1999\/xhtml&quot;},&quot;para&quot;,{&quot;tagName&quot;:&quot;section&quot;,&quot;attributes&quot;:{&quot;style&quot;:&quot;display: inline-block;width: 100%;vertical-align: top;align-self: flex-start;flex: 0 0 auto;background-color: rgb(245, 248, 251);border-left: 5px solid rgb(30, 105, 206);box-sizing: border-box;&quot;},&quot;namespaceURI&quot;:&quot;http:\/\/www.w3.org\/1999\/xhtml&quot;}]\">\n<section>\n<section>\n<section>\n<section>\n<section>\n<h1><strong>03 <\/strong><strong>\u4e8b\u4ef6\u65f6\u95f4\u7ebf<\/strong><\/h1>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<\/section>\n<p>2026 \u5e74 4 \u6708 22 \u65e5 18:56 \u00a0\u4e0a\u6e38\u53d1\u5e03 1.3.5 \u7248\u672c<\/p>\n<p>2026 \u5e74 4 \u6708 22 \u65e5 19:31 \u00a0 \u4e0a\u6e38\u53d1\u5e03<\/p>\n<p>2026 \u5e74 4 \u6708 22 \u65e5 20:30 \u00a0deepin \u76d1\u6d4b\u5230\u8be5\u6f0f\u6d1e\u4fe1\u606f<\/p>\n<p>2026 \u5e74 4 \u6708 23 \u65e5 09:56 \u00a0\u8fdb\u884c\u6f0f\u6d1e\u4fee\u8865\u5e76\u96c6\u6210<\/p>\n<p>2026 \u5e74 4 \u6708 23 \u65e5 13:15 \u00a0 \u96c6\u6210\u6d4b\u8bd5\u901a\u8fc7<\/p>\n<p>2026 \u5e74 4 \u6708 23 \u65e5 16:58 \u00a0\u5df2\u96c6\u6210\u5e76\u5f00\u59cb\u8fdb\u884c\u63a8\u9001<\/p>\n<p>&nbsp;<\/p>\n<section><\/section>\n<section><strong>\u53c2\u8003\u8d44\u6599\uff1a<\/strong><\/section>\n<ul class=\"list-paddingleft-1\">\n<li><span spellcheck=\"false\">https:\/\/lists.freedesktop.org\/archives\/packagekit\/2026-April\/026513.html<\/span><\/li>\n<li><span spellcheck=\"false\">https:\/\/github.security.telekom.com\/2026\/04\/pack2theroot-linux-local-privilege-escalation.html<\/span><\/li>\n<li><span spellcheck=\"false\">https:\/\/github.com\/PackageKit\/PackageKit\/security\/advisories\/GHSA-f55j-vvr9-69xv<\/span><\/li>\n<li><span spellcheck=\"false\">https:\/\/www.openwall.com\/lists\/oss-security\/2026\/04\/22\/6<\/span><\/li>\n<li><span spellcheck=\"false\">https:\/\/github.com\/PackageKit\/PackageKit\/commit\/76cfb675fb31acc3ad5595d4380bfff56d2a8697<\/span><\/li>\n<\/ul>\n<hr \/>\n<section><span data-pm-slice=\"0 0 []\">\u4ee5\u4e0a\u5c31\u662f\u672c\u6b21 deepin 25.1 \u6b63\u5f0f\u7248\u7684\u5168\u90e8\u66f4\u65b0\u5185\u5bb9\u5566\uff0c\u518d\u6b21\u611f\u8c22\u6bcf\u4e00\u4f4d deepin \u793e\u533a\u670b\u53cb\u7684\u652f\u6301\uff01<\/span><\/section>\n<section>deepin \u4f5c\u4e3a\u5728<a href=\"https:\/\/distrowatch.com\/table.php?distribution=deepin\" data-lark-is-custom=\"true\">\u00a0DistroWatch \u5168\u7403\u6392\u540d\u4e2d\u8868\u73b0\u4eae\u773c\u3001\u5e7f\u53d7\u5168\u7403\u7528\u6237\u8ba4\u53ef\u7684\u5f00\u6e90\u64cd\u4f5c\u7cfb\u7edf<\/a><strong>\uff0c<\/strong>\u6301\u7eed\u8fed\u4ee3\u6f0f\u6d1e\u54cd\u5e94\uff0c\u5168\u529b\u6253\u9020\u7a33\u5b9a\u53ef\u4fe1\u3001\u5b89\u5168\u65e0\u5fe7\u7684\u5f00\u6e90\u684c\u9762\u751f\u6001\u00a0\u3002<\/section>\n<section><\/section>\n<section><span data-pm-slice=\"0 0 []\">\u5982\u60a8\u5728\u66f4\u65b0\u6216\u4f7f\u7528\u8fc7\u7a0b\u4e2d\u9047\u5230\u4efb\u4f55\u95ee\u9898\uff0c\u6b22\u8fce\u524d\u5f80\u00a0<a class=\"weapp_text_link js_weapp_entry wx_tap_link js_wx_tap_highlight\" href=\"https:\/\/bbs.deepin.org\/post\/297561\" data-unique-id=\"mobavlul-rriu2v\" data-miniprogram-type=\"text\" data-miniprogram-appid=\"wxcf1a4dbefee5cb41\" data-miniprogram-path=\"pages\/thread\/thread?id=297561\" data-miniprogram-nickname=\"deepin\u793e\u533a\u8bba\u575b\" data-miniprogram-servicetype=\"0\" data-miniprogram-applink=\"#\u5c0f\u7a0b\u5e8f:\/\/deepin\u8bba\u575b\/\u5e16\u5b50\u8be6\u60c5\/DVitFhN5gh3O95o\">deepin\u793e\u533a\u8bba\u575b<\/a>\u4ea4\u6d41\u53cd\u9988\u3002<\/span><\/section>","protected":false},"excerpt":{"rendered":"<p>\ud83d\udd14\u00a0\u4eb2\u7231\u7684 deepin \u7528\u6237\u4e0e\u793e\u533a\u4f19\u4f34\u4eec\uff0c deepin 25.1 \u66f4\u65b0\u6765\u5566\uff01\u672c\u6b21\u66f4\u65b0\u6d89\u53ca\u6700\u65b0\u201cPack2TheRoot\u201d \u9ad8\u5371\u6f0f\u6d1e\u7d27\u6025\u4fee\u590d\uff0c\u540c\u65f6\u9488\u5bf9\u8fd1\u671f\u5347\u7ea7\u7528\u6237\u97f3\u9891\u8bbe\u5907\u4e22\u5931\u95ee\u9898\u8fdb\u884c\u4e86\u4f18\u5316\uff0c\u5f3a\u70c8\u5efa\u8bae\u5927\u5bb6\u7b2c\u4e00\u65f6\u95f4\u66f4\u65b0\u5347\u7ea7\u3002 &nbsp; 01 2026\u5e744\u670823\u65e5 \u66f4\u65b0\u8be6\u60c5 \u4fee\u590d\u90e8\u5206\u7528\u6237\u97f3\u9891\u8bbe\u5907\u4e22\u5931\u95ee\u9898\uff1b \u4fee\u6539\u79fb\u9664\u90e8\u5206\u5931\u6548\u667a\u80fd\u955c\u50cf\u6e90\uff0c\u4fee\u590d\u90e8\u5206\u7528\u6237\u56e0IP\u88ab\u7981\u6b62\u5bfc\u81f4\u7684\u66f4\u65b0\u5931\u8d25\u95ee\u9898\uff1b \u4fee\u590d\u90e8\u5206\u5df2\u77e5CVE ...<a href=https:\/\/www.deepin.org\/zh\/deepin-25-1-upgrade-announcement-260423\/>\u9605\u8bfb\u66f4\u591a<\/a><\/p>\n","protected":false},"author":18825,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[93],"tags":[],"_links":{"self":[{"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/posts\/38886"}],"collection":[{"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/users\/18825"}],"replies":[{"embeddable":true,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/comments?post=38886"}],"version-history":[{"count":7,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/posts\/38886\/revisions"}],"predecessor-version":[{"id":38895,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/posts\/38886\/revisions\/38895"}],"wp:attachment":[{"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/media?parent=38886"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/categories?post=38886"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.deepin.org\/zh\/wp-json\/wp\/v2\/tags?post=38886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}