[Pkg-utopia-maintainers] Bug#1142416: pipewire: CVE-2026-5674

Salvatore Bonaccorso carnil at debian.org
Sun Jul 19 15:16:29 BST 2026


Source: pipewire
Version: 1.6.8-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerability was published for pipewire.

Can you please check with upstream, at time of writing this bugreport
only the Red Hat bugzilla entry was available. So it is unclear if
this is known upstream, tracked upstream, fixed upstream or else.

CVE-2026-5674[0]:
| A flaw was found in PipeWire, a multimedia server. This
| vulnerability allows an attacker to escape sandboxed applications,
| such as Flatpak, by exploiting PipeWire's PulseAudio compatibility
| layer. An attacker with minimal permissions within a sandboxed
| environment can load a malicious library, leading to arbitrary code
| execution outside the sandbox and potential compromise of the user's
| system.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5674
    https://www.cve.org/CVERecord?id=CVE-2026-5674
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2455341

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-utopia-maintainers mailing list