CVE-2026-97029 MEDIUM

CVE-2026-97029: Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Weakness CWE-653
Published September 29, 2026
Last update September 29, 2026

CVSS base score

5.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.

Key dates

02Disclosure timeline

September 29, 2026 CVE published
September 29, 2026 Record updated