CVE-2026-5674: Red Hat Enterprise Linux 10
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:1.4.11-1.el10_2 (fixed in 0:1.4.11-1.el10_2)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:1.2.7-1.el10_0.1 (fixed in 0:1.2.7-1.el10_0.1)
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 0:1.4.11-1.el9_8 (fixed in 0:1.4.11-1.el9_8)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:0.3.47-4.el9_2.1 (fixed in 0:0.3.47-4.el9_2.1)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:1.0.1-1.el9_4.1 (fixed in 0:1.0.1-1.el9_4.1)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:1.0.1-1.el9_6.1 (fixed in 0:1.0.1-1.el9_6.1)
Published 2026-07-16. Last modified 2026-08-31.