Sceawere
Vulnerability Detail
CVE-2026-97029UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Flatpak Sandbox Process Group Escape
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.7
- Creation Date
- 3h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Improper Isolation or Compartmentalization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.7",
"pubDate": "2026-09-29T04:18:02.573Z",
"pubdate": "2026-09-29T04:18:02.573Z",
"executiveSummary": "This vulnerability involves a critical flaw in Flatpak's process ID (PID) namespace implementation regarding process group isolation. An attacker-controlled or compromised application within the Flatpak sandbox can interact with processes outside its intended security boundary by targeting process groups.\nThe vulnerability is classified as a sandbox escape and privilege escalation vector, specifically involving improper access control in process signaling. The primary impact is a Denial of Service (DoS), where a sandboxed application can terminate critical system processes, such as the desktop shell or session manager, by sending signals to the entire process group.\nThis flaw affects Flatpak environments where the sandbox does not adequately restrict kill(0, signal) or killpg(0, signal) syscalls. The risk is significant, as it allows a sandboxed entity to disrupt host-level services without requiring elevated privileges. Exploitation requires only the ability to execute code within a Flatpak-contained application. There are no authentication requirements for the exploit, as it leverages inherent system-level process signaling mechanisms that the sandbox currently fails to intercept or sanitize, effectively bypassing the namespace-based containment intended to protect the host environment.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient enforcement of the PID namespace abstraction within the Flatpak runtime environment. While Flatpak utilizes Linux namespaces to isolate the application's view of the process table, it fails to account for the semantics of the kill(0, signal) and killpg(0, signal) syscalls as they interact with process groups.\nWhen a sandboxed process invokes kill(0, signal), the kernel interprets the destination as the entire process group (PGID) to which the sender belongs. Due to the incomplete isolation of these process groups, if a sandboxed process shares a process group identifier with external host-level processes or if the signaling mechanism traverses the namespace boundary incorrectly, the signal is propagated to those external processes.\nThe exploitation flow proceeds as follows: First, an attacker initiates a malicious or compromised application within a Flatpak container. Second, the application invokes the killpg(0, signal) or kill(0, signal) syscalls. Third, because the sandbox environment lacks appropriate seccomp filtering or namespace mediation to intercept these specific signal targets, the kernel dispatches the signal to all processes within the sender's process group. If the process group mapping incorrectly associates the sandbox with critical host-level processes, these external entities receive the signal.\nThe payload behavior is inherently disruptive; by sending a termination signal (such as SIGTERM or SIGKILL) to the entire process group, the sandboxed process effectively forces a shutdown or crash of any process sharing that group, including the desktop environment or user session shell. Because this interaction occurs at the kernel level via standard process signaling, it bypasses user-space sandbox constraints.\nThe vulnerable component is the Flatpak process management and sandboxing logic, specifically the part responsible for enforcing signal isolation. The vulnerability persists in environments where Flatpak relies solely on PID namespace virtualization without additional seccomp-based restrictions on signal-sending syscalls. The exploit is highly reliable as it relies on standard POSIX signaling behavior, and post-exploitation, the impact is immediate loss of service or system stability, essentially resulting in a functional DoS of the affected desktop session."
}