CVE-2026-97029

EUVD-2026-88627
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.7 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 14.07%
Debian logo
Debian Releases
Debian Product
Codename
flatpak
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
1.18.4-1
fixed
trixie
vulnerable
trixie (security)
1.16.6-1~deb13u3
fixed