CVE-2026-97029

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-653

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
Full discourse1 post
  • LinuxSecurity@lnxsec

    “Sandboxed” can become a dangerously broad trust label. Flatpak isolates applications, but recent vulnerabilities show that isolation has several edges: filesystem path resolution during deployment, privileged helper behavior, and process-group signaling. CVE-2026-97029 is especially useful as a reminder. PID namespace separation did not stop a sandboxed app from signaling unsandboxed processes that shared its process group, potentially terminating components such as the desktop shell. That is not the same impact as reading arbitrary host files or gaining code execution. It is still a boundary failure administrators should understand rather than flatten into a single “sandbox escape” label. **In practical terms, it is a good time to:** - verify the Flatpak build actually installed on managed endpoints - identify distributions using backported fixes rather than relying on upstream version numbers alone - test whether untrusted Flatpak workloads can affect parent-session processes - review endpoint recovery behavior when the desktop shell or session components terminate unexpectedly How often do your security reviews test what a sandbox can influence outside itself, rather than only what it can read or write? #Linux #LinuxSecurity #DesktopSecurity #OpenSource #SecurityOperations https://linuxsecurity.com/features/flatpak-vulnerability-linux-host-files-processes

    0000074
    4.5K followersView on X

Explore more