Tagged articles

PipeWire

3 articles · Page 1 of 1
Black & White Path
Black & White Path
Aug 2, 2026 · Information Security

How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code

The analysis of CVE‑2026‑5674 reveals that PipeWire’s PulseAudio compatibility layer contains three independent flaws—a missing cookie verification, default‑enabled module loading, and unrestricted dlopen() paths—that together let a sandboxed Flatpak app with only audio permission write files, launch desktop applications, and run arbitrary code on the host.

CVE-2026-5674FlatpakPipeWire
0 likes · 15 min read
How a Simple "Hello World" Flatpak App Escapes the PipeWire Sandbox to Execute Arbitrary Code
Ubuntu
Ubuntu
Feb 28, 2025 · Industry Insights

Ubuntu 24.04 LTS vs 22.04: Disruptive New Features and Long-Term Support

Ubuntu 24.04 LTS (Noble Numbat) introduces a Flutter‑based installer, GNOME 46 desktop, Linux 6.8 kernel, PipeWire as the default audio server, Thunderbird 115 as the default mail client, enhanced AppArmor and frame‑pointer security, broader hardware support and an optional 12‑year Ubuntu Pro support window, marking a substantial upgrade over 22.04.

AppArmorFlutter installerGNOME 46
0 likes · 7 min read
Ubuntu 24.04 LTS vs 22.04: Disruptive New Features and Long-Term Support