Junglewise Threat Intelligence

CVE-2026-5674: PipeWire sandbox escape via PulseAudio compatibility layer

CVE-2026-5674 · Severity: high · CVSS 8.8 · Published 2026-07-16

Technologies: PipeWire Project PipeWire, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9. Vendors: Red Hat.

Executive brief

PipeWire is a multimedia server used in Linux operating systems to manage audio and video streams. A security flaw in its PulseAudio compatibility layer allows a malicious application to break out of its restricted 'sandbox' (such as Flatpak) and execute code on the host system. This could allow an attacker to bypass security boundaries, access private user data, and take full control of the user's session.

Technical details

A vulnerability classified as CWE-427 (Uncontrolled Search Path Element) exists in PipeWire's PulseAudio compatibility layer, specifically within 'module-protocol-pulse' and 'module-ladspa-sink'. An attacker within a sandboxed environment (e.g., Flatpak) with access to the PulseAudio socket and a writable host-visible directory can load a malicious shared library (.so) via the PA_COMMAND_LOAD_MODULE command. Because PipeWire executes outside the sandbox and calls dlopen() on the provided path without sufficient path validation, the library's constructor executes in the full context of the user session. Mitigations include setting 'pulse.allow-module-loading = false' or restricting dlopen() paths to trusted system directories.

Affected products

  • PipeWire Project PipeWire <= 1.0.5
  • Red Hat Red Hat Enterprise Linux 9 affected
  • Red Hat Red Hat Enterprise Linux 10 affected

Timeline

  • 2026-04-06: other: Initial report in Red Hat Bugzilla
  • 2026-07-16: disclosed: CVE published to NVD

References

Related threats