CVE-2026-97029
Last modified
CVE-2026-97029 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell..
Description
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | All versions |
| Red Hat | Red Hat Enterprise Linux 7 | All versions |
| Red Hat | Red Hat Enterprise Linux 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 9 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-97029?
How severe is CVE-2026-97029?
How do I fix CVE-2026-97029?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9702The InPost PL WordPress plugin before 1.9.1 does not verify …7.5
- CVE-2026-97023A path traversal vulnerability in Flatpak's handling of the …7.1
- CVE-2026-97024A path traversal vulnerability in Flatpak's handling of the …7.1
- CVE-2026-97025Flatpak writes the OCI repository authentication token with …3.2
- CVE-2026-97026Flatpak creates temporary child repository directories under…3.9
- CVE-2026-97027Flatpak passes through arbitrary vendor-extension keys unmod…3.6
- CVE-2026-9704A flaw was found in Keycloak. An authenticated user with low…8.8
- CVE-2026-9705A flaw was found in Keycloak's client registration service. …6.5
- CVE-2026-97055SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenize…8.1
- CVE-2026-97056SigNoz versions from v0.98.0 up to (but not including) v0.14…6.8
- CVE-2026-97057redis-parser through 3.0.0 fails to validate the multi-bulk …7.5
- CVE-2026-97058sprintf-js through 1.1.3 passes unbounded precision specifie…5.3
Are you affected by CVE-2026-97029?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
