
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-97029 is a sandbox escape/denial-of-service vulnerability in Flatpak caused by improper process ID namespace isolation. A sandboxed Flatpak application can invoke kill(0, signal) or killpg(0, signal) to send signals to all processes sharing the same process group, including processes outside the sandbox such as the desktop shell. All Flatpak versions prior to 1.18.4 are affected. The vulnerability was disclosed on September 28, 2026, and carries a CVSS v3.1 base score of 5.7 (Medium) (Red Hat CVE, GitHub Advisory).
The root cause is classified as CWE-653 (Improper Isolation or Compartmentalization): Flatpak's use of Linux process ID namespaces via bubblewrap does not fully isolate signal delivery when a sandboxed process calls kill(0, signal) or killpg(0, signal) (GitHub Advisory). In Linux, kill(0, sig) sends a signal to every process in the caller's process group; because the sandboxed app shares a process group with its parent (the Flatpak launcher) and potentially other desktop processes, the signal escapes the PID namespace boundary (Red Hat Bugzilla). Exploitation requires the victim to install and run a malicious or compromised Flatpak app; no additional privileges beyond those of a normal sandboxed app are needed. The fix (commit a3cf27b5) places each bubblewrap child process in its own process group, preventing the signal from reaching processes outside the sandbox (Red Hat Bugzilla).
The primary impact is availability: a malicious or compromised Flatpak app can terminate critical processes outside its sandbox that share the same process group, such as GNOME Shell, causing the user's entire desktop session to end (GitHub Advisory). There is no confidentiality or integrity impact under normal conditions; however, if processes in the same process group respond unsafely to certain signals (e.g., SIGUSR1 enabling additional attack surface), a secondary exploitation path could emerge (Red Hat CVE). The scope is limited to the local host and does not enable lateral movement to other systems.
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Red Hat CVE). The EPSS score is 0.0, reflecting very low current exploitation probability (ENISA EUVD). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires user interaction — a victim must install and run a malicious or compromised Flatpak application — which limits opportunistic exploitation (GitHub Advisory).
kill(0, SIGTERM) or killpg(0, SIGKILL) (or another signal), which Linux delivers to all processes in the same process group — including those outside the PID namespace.gnome-shell) logged in systemd journal (journalctl) with signal-related exit codes (e.g., killed by SIGTERM or SIGKILL) shortly after launching a Flatpak application.gnome-shell, plasmashell) correlated in time with a running Flatpak sandbox process; audit logs showing kill syscalls with PID 0 originating from a bubblewrap-sandboxed process.flatpak list --app and flatpak remotes).Upgrade Flatpak to version 1.18.4 or later, which places each bubblewrap child process in its own process group via commit a3cf27b5, preventing signal leakage outside the sandbox (GitHub Advisory). As a temporary workaround, run Flatpak apps in a new session using setsid flatpak run <app> or in a new process group by calling setpgid(0, 0) in the parent process before launching the app (Red Hat CVE). Users should also avoid installing and running untrusted Flatpak applications until the patch is applied.
The vulnerability was reported by Guthrie Armstrong of Coalition, Inc. and received coverage from Linux-focused outlets including Linuxiac and Tux Machines, which highlighted the Flatpak 1.18.4 release as fixing six security vulnerabilities including this issue (Linuxiac, Tux Machines). Community discussion on platforms such as programming.dev and Privacy Guides forums noted the sandbox escape implications for desktop security (Privacy Guides Forum). The oss-security mailing list also carried the disclosure (oss-sec).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
flatpak
devel
flatpak
focal (esm-apps)
flatpak
jammy
flatpak
jammy (esm-apps)
flatpak
noble
flatpak
noble (esm-apps)
flatpak
resolute
flatpak
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."