CVE-2026-5674

NameCVE-2026-5674
DescriptionA flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1142416

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pipewire (PTS)bookworm0.3.65-3+deb12u1vulnerable
trixie1.4.2-1vulnerable
forky, sid1.6.9-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pipewiresource(unstable)1.6.6-11142416

Notes

[trixie] - pipewire <no-dsa> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2455341
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/6bc07dfe0e18043aaf99f866b2c37f20e4a5e065 (1.6.3)
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/821b62dac5f9718b9d5d48ca967f4c4b6954bda2 (1.6.3)
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/8be0d7534b8642b37ae53895e0c82e680b2b4a73 (1.6.4)
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/0b11792194f2ee985f8a8f15776ccec357bc8097 (1.6.5)
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/aae60d8db3b0f1a1a52e2999e188ed9721b287f9 (1.6.6)

Search for package or bug name: Reporting problems