Beveiligingsadvies

CVE-2026-5674

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-16 13:26:44
Laatst bijgewerkt 2026-08-31 19:51:13
Toegewezen door redhat
CVSS-score 8.8
Status PUBLISHED

Beschrijving

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.