| Name | CVE-2026-5674 |
| Description | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1142416 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| pipewire (PTS) | bookworm | 0.3.65-3+deb12u1 | vulnerable |
| trixie | 1.4.2-1 | vulnerable | |
| forky, sid | 1.6.9-2 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| pipewire | source | (unstable) | 1.6.6-1 | 1142416 |
[trixie] - pipewire <no-dsa> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2455341
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/6bc07dfe0e18043aaf99f866b2c37f20e4a5e065 (1.6.3)
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/821b62dac5f9718b9d5d48ca967f4c4b6954bda2 (1.6.3)
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/8be0d7534b8642b37ae53895e0c82e680b2b4a73 (1.6.4)
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/0b11792194f2ee985f8a8f15776ccec357bc8097 (1.6.5)
Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/aae60d8db3b0f1a1a52e2999e188ed9721b287f9 (1.6.6)