8.8 CVE-2026-5674

Enriched by CISA
 

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
https://nvd.nist.gov/vuln/detail/CVE-2026-5674

Categories

CWE-427 : Uncontrolled Search Path Element

References


 

AFFECTED (from MITRE)


Vendor Product Versions
Red Hat Red Hat Enterprise Linux 10
  • 0:1.4.11-1.el10_2 < * [unaffected]
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
  • 0:1.2.7-1.el10_0.1 < * [unaffected]
Red Hat Red Hat Enterprise Linux 9
  • 0:1.4.11-1.el9_8 < * [unaffected]
Red Hat Red Hat Enterprise Linux 10
    Red Hat Red Hat Enterprise Linux 10
      Red Hat Red Hat Enterprise Linux 7
        Red Hat Red Hat Enterprise Linux 8
          Red Hat Red Hat Enterprise Linux 8
            Red Hat Red Hat Enterprise Linux 8
              Red Hat Red Hat Enterprise Linux 9
                © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

                CPE

                cpe start end


                REMEDIATION




                EXPLOITS


                Exploit-db.com

                id description date
                No known exploits

                POC Github

                Url
                No known exploits

                Other Nist (github, ...)

                Url
                No known exploits


                CAPEC


                Common Attack Pattern Enumerations and Classifications

                id description severity
                38 Leveraging/Manipulating Configuration File Search Paths
                Very High
                471 Search Order Hijacking
                Medium


                MITRE


                Techniques

                id description
                T1574.001 Hijack Execution Flow:DLL search order hijacking
                T1574.004 Hijack Execution Flow: Dylib Hijacking
                T1574.007 Hijack Execution Flow:Path Interception by PATH Environment Variable
                T1574.008 Hijack Execution Flow:Path Interception by Search Order Hijacking
                T1574.009 Hijack Execution Flow: Path Interception by Unquoted Path
                © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

                Mitigations

                id description
                M1044 Disallow loading of remote DLLs. This is included by default in Windows Server 2012+ and is available by patch for XP+ and Server 2003+. Enable Safe DLL Search Mode to force search for system DLLs in directories with greater restrictions (e.g. <code>%SYSTEMROOT%</code>)to be used before local directory DLLs (e.g. a user's home directory) The Safe DLL Search Mode can be enabled via Group Policy at Computer Configuration > [Policies] > Administrative Templates > MSS (Legacy): MSS: (SafeDllSearchMode) Enable Safe DLL search mode. The associated Windows Registry key for this is located at <code>HKLMSYSTEMCurrentControlSetControlSession ManagerSafeDLLSearchMode</code>
                M1022 Set directory access controls to prevent file writes to the search paths for applications, both in the folders where applications are run from and the standard dylib folders.
                M1022 Ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory <code>C:</code> and system directories, such as <code>C:Windows</code>, to reduce places where malicious files could be placed for execution. Require that all executables be placed in write-protected directories.
                M1022 Ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory <code>C:</code> and system directories, such as <code>C:Windows</code>, to reduce places where malicious files could be placed for execution. Require that all executables be placed in write-protected directories.
                M1022 Ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory <code>C:</code> and system directories, such as <code>C:Windows</code>, to reduce places where malicious files could be placed for execution. Require that all executables be placed in write-protected directories.
                © 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation.