pipewire-1.4.11-1.el9_8 | MIRACLE LINUX
PipeWire is a multimedia server for Linux and other Unix like operating systems.
Security Fix(es):
* pipewire: PipeWire: Sandbox escape and arbitrary code execution via malicious library loading (CVE-2026-5674)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-5674
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire’s PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user’s system.
Read more here: Source link
