Описание
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
Отчет
Important: This flaw in PipeWire allows for a sandbox escape, enabling arbitrary code execution outside of sandboxed environments, such as Flatpak applications, when minimal permissions are granted. Red Hat products utilizing PipeWire's PulseAudio compatibility layer are susceptible, as an attacker can load a malicious library from within a sandboxed process, bypassing isolation mechanisms.
Меры по смягчению последствий
To mitigate this issue, restrict containerized applications from accessing the PulseAudio socket or writing to host-visible paths. Additionally, configure PipeWire to prevent module loading by setting pulse.allow-module-loading = false in the PipeWire PulseAudio configuration. Alternatively, restrict the dlopen() paths for module-ladspa-sink to trusted system directories like /usr/lib/ladspa/ and /usr/lib64/ladspa/. Applying these changes may require restarting the PipeWire service to take effect, which could impact audio functionality.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox | Not affected | ||
| Red Hat Enterprise Linux 10 | libkrun | Not affected | ||
| Red Hat Enterprise Linux 7 | firefox | Not affected | ||
| Red Hat Enterprise Linux 8 | firefox | Not affected | ||
| Red Hat Enterprise Linux 8 | pipewire | Not affected | ||
| Red Hat Enterprise Linux 8 | pipewire0.2 | Not affected | ||
| Red Hat Enterprise Linux 9 | firefox | Not affected | ||
| Red Hat Enterprise Linux 9 | pipewire | Affected | ||
| Red Hat Enterprise Linux 10 | pipewire | Fixed | RHSA-2026:47083 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
A flaw was found in PipeWire, a multimedia server. This vulnerability ...
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
EPSS
8.8 High
CVSS3