Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-47083

Опубликовано: 28 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-47083: pipewire security update (IMPORTANT)

[1.4.11-1]

  • Rebase to 1.4.11
  • Add fixes for CVE-2026-5674 Resolves: RHEL-164823

[1.4-6-1]

  • Update version to 1.4.6 Resolves: DESKTOP-1857

[1.2.7-1]

  • Update version to 1.2.7
  • Resolves: RHEL-76017

[1.2.6-3]

  • Enable libcamera support in RHEL-10
  • Resolves: RHEL-64753

[1.2.6-2]

  • Bump release for October 2024 mass rebuild: Resolves: RHEL-64018

[1.2.6-1]

  • Update version to 1.2.6

[1.2.3-1]

  • Update version to 1.2.3

[1.2.1-3]

  • pipewire-jack-libs Requires pipewire-jack on RHEL

[1.2.1-2]

[1.2.1-1]

  • Update version to 1.2.1

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

pipewire

1.4.11-1.el10_2

pipewire-alsa

1.4.11-1.el10_2

pipewire-devel

1.4.11-1.el10_2

pipewire-gstreamer

1.4.11-1.el10_2

pipewire-jack-audio-connection-kit

1.4.11-1.el10_2

pipewire-jack-audio-connection-kit-devel

1.4.11-1.el10_2

pipewire-jack-audio-connection-kit-libs

1.4.11-1.el10_2

pipewire-libs

1.4.11-1.el10_2

pipewire-module-x11

1.4.11-1.el10_2

pipewire-plugin-libcamera

1.4.11-1.el10_2

pipewire-pulseaudio

1.4.11-1.el10_2

pipewire-utils

1.4.11-1.el10_2

Oracle Linux x86_64

pipewire

1.4.11-1.el10_2

pipewire-alsa

1.4.11-1.el10_2

pipewire-devel

1.4.11-1.el10_2

pipewire-gstreamer

1.4.11-1.el10_2

pipewire-jack-audio-connection-kit

1.4.11-1.el10_2

pipewire-jack-audio-connection-kit-devel

1.4.11-1.el10_2

pipewire-jack-audio-connection-kit-libs

1.4.11-1.el10_2

pipewire-libs

1.4.11-1.el10_2

pipewire-module-x11

1.4.11-1.el10_2

pipewire-plugin-libcamera

1.4.11-1.el10_2

pipewire-pulseaudio

1.4.11-1.el10_2

pipewire-utils

1.4.11-1.el10_2

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
15 дней назад

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

CVSS3: 8.8
redhat
27 дней назад

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

CVSS3: 8.8
nvd
15 дней назад

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

CVSS3: 8.8
debian
15 дней назад

A flaw was found in PipeWire, a multimedia server. This vulnerability ...

CVSS3: 8.8
github
15 дней назад

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.