pipewire-1.4.11-1.el9_8 | MIRACLE LINUX

PipeWire is a multimedia server for Linux and other Unix like operating systems.

Security Fix(es):

* pipewire: PipeWire: Sandbox escape and arbitrary code execution via malicious library loading (CVE-2026-5674)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-5674
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire’s PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user’s system.

Read more here: Source link