CVE-2026-97029: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-97029 is a sandbox escape/denial-of-service vulnerability in Flatpak caused by improper process ID namespace isolation. A sandboxed Flatpak application can invoke kill(0, signal) or killpg(0, signal) to send signals to all processes sharing the same process group, including processes outside the sandbox such as the desktop shell. All Flatpak versions prior to 1.18.4 are affected. The vulnerability was disclosed on September 28, 2026, and carries a CVSS v3.1 base score of 5.7 (Medium) (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is classified as CWE-653 (Improper Isolation or Compartmentalization): Flatpak's use of Linux process ID namespaces via bubblewrap does not fully isolate signal delivery when a sandboxed process calls kill(0, signal) or killpg(0, signal) (GitHub Advisory). In Linux, kill(0, sig) sends a signal to every process in the caller's process group; because the sandboxed app shares a process group with its parent (the Flatpak launcher) and potentially other desktop processes, the signal escapes the PID namespace boundary (Red Hat Bugzilla). Exploitation requires the victim to install and run a malicious or compromised Flatpak app; no additional privileges beyond those of a normal sandboxed app are needed. The fix (commit a3cf27b5) places each bubblewrap child process in its own process group, preventing the signal from reaching processes outside the sandbox (Red Hat Bugzilla).

Impact

The primary impact is availability: a malicious or compromised Flatpak app can terminate critical processes outside its sandbox that share the same process group, such as GNOME Shell, causing the user's entire desktop session to end (GitHub Advisory). There is no confidentiality or integrity impact under normal conditions; however, if processes in the same process group respond unsafely to certain signals (e.g., SIGUSR1 enabling additional attack surface), a secondary exploitation path could emerge (Red Hat CVE). The scope is limited to the local host and does not enable lateral movement to other systems.

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Red Hat CVE). The EPSS score is 0.0, reflecting very low current exploitation probability (ENISA EUVD). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires user interaction — a victim must install and run a malicious or compromised Flatpak application — which limits opportunistic exploitation (GitHub Advisory).

Exploitation steps

  1. Distribute a malicious Flatpak app: An attacker creates or compromises a Flatpak application and distributes it via a Flatpak repository or sideloading, targeting users running desktop environments such as GNOME Shell.
  2. Victim installs and runs the app: The victim installs and launches the malicious Flatpak app, which runs inside a bubblewrap sandbox with a PID namespace but shares the process group of the Flatpak launcher.
  3. Issue a broadcast signal: From within the sandbox, the malicious app calls kill(0, SIGTERM) or killpg(0, SIGKILL) (or another signal), which Linux delivers to all processes in the same process group — including those outside the PID namespace.
  4. Terminate out-of-sandbox processes: Processes such as GNOME Shell or other desktop components that share the process group receive the signal and terminate, ending the user's desktop session and causing denial of service (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Unexpected termination of desktop shell processes (e.g., gnome-shell) logged in systemd journal (journalctl) with signal-related exit codes (e.g., killed by SIGTERM or SIGKILL) shortly after launching a Flatpak application.
  • Process: Sudden disappearance of the desktop session process (e.g., gnome-shell, plasmashell) correlated in time with a running Flatpak sandbox process; audit logs showing kill syscalls with PID 0 originating from a bubblewrap-sandboxed process.
  • File System: Presence of newly installed or sideloaded Flatpak applications from untrusted or unknown remotes (check flatpak list --app and flatpak remotes).

Mitigation and workarounds

Upgrade Flatpak to version 1.18.4 or later, which places each bubblewrap child process in its own process group via commit a3cf27b5, preventing signal leakage outside the sandbox (GitHub Advisory). As a temporary workaround, run Flatpak apps in a new session using setsid flatpak run <app> or in a new process group by calling setpgid(0, 0) in the parent process before launching the app (Red Hat CVE). Users should also avoid installing and running untrusted Flatpak applications until the patch is applied.

Community reactions

The vulnerability was reported by Guthrie Armstrong of Coalition, Inc. and received coverage from Linux-focused outlets including Linuxiac and Tux Machines, which highlighted the Flatpak 1.18.4 release as fixing six security vulnerabilities including this issue (Linuxiac, Tux Machines). Community discussion on platforms such as programming.dev and Privacy Guides forums noted the sandbox escape implications for desktop security (Privacy Guides Forum). The oss-security mailing list also carried the disclosure (oss-sec).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

flatpak

Affected

sid

flatpak: 1.18.4-1

Fixed

trixie

flatpak: 1.16.6-1~deb13u3

Fixed

Ubuntu

Unknown

bionic (esm-apps)

flatpak

Unknown

devel

flatpak

Unknown

focal (esm-apps)

flatpak

Unknown

jammy

flatpak

Unknown

jammy (esm-apps)

flatpak

Unknown

noble

flatpak

Unknown

noble (esm-apps)

flatpak

Unknown

resolute

flatpak

Unknown

RHEL / CentOS

Affected

RHEL 8

flatpak.src

Affected

RHEL 9

flatpak.src

Affected

RHEL 10

flatpak.src

Affected

Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97024HIGH7.1
  • Linux Debian logoLinux Debian
  • flatpak-selinux
NoYesSep 29, 2026
CVE-2026-97029MEDIUM5.7
  • Linux Debian logoLinux Debian
  • flatpak-devel
NoYesSep 29, 2026
CVE-2026-97026LOW3.9
  • Linux Debian logoLinux Debian
  • flatpak-selinux
NoYesSep 28, 2026
CVE-2026-97027LOW3.6
  • Linux Debian logoLinux Debian
  • flatpak-devel
NoYesSep 28, 2026
CVE-2026-97025LOW3.2
  • Linux Debian logoLinux Debian
  • flatpak-session-helper
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management