Medium severity5.7NVD Advisory· Published Sep 29, 2026
CVE-2026-97029
CVE-2026-97029
Description
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.