CVE-2026-5674
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Summary
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
0 <= 1.6.8 | affected | ||
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.4.11-1.el10_2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:1.2.7-1.el10_0.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.4.11-1.el9_8 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:1.0.1-1.el9_4.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.0.1-1.el9_6.1 < * | unaffected |
Weaknesses
- CWE-427: Uncontrolled Search Path Element
Workarounds
To mitigate this issue, restrict containerized applications from accessing the PulseAudio socket or writing to host-visible paths. Additionally, configure PipeWire to prevent module loading by setting pulse.allow-module-loading = false in the PipeWire PulseAudio configuration. Alternatively, restrict the dlopen() paths for module-ladspa-sink to trusted system directories like /usr/lib/ladspa/ and /usr/lib64/ladspa/. Applying these changes may require restarting the PipeWire service to take effect, which could impact audio functionality.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://access.redhat.com/errata/RHSA-2026:47082
- https://access.redhat.com/errata/RHSA-2026:47083
- https://access.redhat.com/errata/RHSA-2026:51064
- https://access.redhat.com/errata/RHSA-2026:56028
- https://access.redhat.com/errata/RHSA-2026:56029
- https://access.redhat.com/security/cve/CVE-2026-5674
- https://bugzilla.redhat.com/show_bug.cgi?id=2455341
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.