There are 2 open security issues in trixie.
1 important issue:
- CVE-2026-5674:
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
1 issue left for the package maintainer to handle:
- CVE-2026-14324:
(needs triaging)
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
You can find information about how to handle this issue in the security team's documentation.