Debian Package Tracker
Register | Log in
Subscribe

pipewire

audio and video processing engine multimedia server

Choose email to subscribe with

general
  • source: pipewire (main)
  • version: 1.6.8-1
  • maintainer: Utopia Maintenance Team (archive) (DMD)
  • uploaders: Jeremy Bicha [DMD] – Dylan Aïssi [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.3.19-4
  • oldstable: 0.3.65-3+deb12u1
  • old-bpo: 1.4.2-1~bpo12+1
  • stable: 1.4.2-1
  • stable-bpo: 1.4.9-1~bpo13+2
  • testing: 1.6.8-1
  • unstable: 1.6.8-1
versioned links
  • 0.3.19-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.3.65-3+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.2-1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.9-1~bpo13+2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gstreamer1.0-pipewire (1 bugs: 0, 1, 0, 0)
  • libpipewire-0.3-0t64
  • libpipewire-0.3-common
  • libpipewire-0.3-dev
  • libpipewire-0.3-modules
  • libpipewire-0.3-modules-x11 (1 bugs: 0, 1, 0, 0)
  • libspa-0.2-bluetooth (2 bugs: 0, 2, 0, 0)
  • libspa-0.2-dev
  • libspa-0.2-jack
  • libspa-0.2-libcamera
  • libspa-0.2-modules (1 bugs: 0, 1, 0, 0)
  • pipewire (46 bugs: 0, 41, 5, 0)
  • pipewire-alsa (1 bugs: 0, 1, 0, 0)
  • pipewire-audio (3 bugs: 0, 3, 0, 0)
  • pipewire-audio-client-libraries
  • pipewire-bin (2 bugs: 0, 2, 0, 0)
  • pipewire-doc
  • pipewire-jack (3 bugs: 0, 2, 1, 0)
  • pipewire-libcamera
  • pipewire-pulse (13 bugs: 0, 10, 3, 0)
  • pipewire-system-services (3 bugs: 0, 3, 0, 0)
  • pipewire-tests
  • pipewire-v4l2
action needed
2 security issues in trixie high

There are 2 open security issues in trixie.

1 important issue:
  • CVE-2026-5674: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
1 issue left for the package maintainer to handle:
  • CVE-2026-14324: (needs triaging) RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-07-02 Last update: 2026-08-02 20:32
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-5674: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
Created: 2026-07-18 Last update: 2026-08-02 20:32
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-5674: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
Created: 2026-07-18 Last update: 2026-08-02 20:32
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-5674: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
Created: 2026-07-18 Last update: 2026-08-02 20:32
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-5674: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
1 issue postponed or untriaged:
  • CVE-2026-14324: (postponed; to be fixed through a stable update) RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Created: 2026-07-02 Last update: 2026-08-02 20:32
3 bugs tagged patch in the BTS normal
The BTS contains patches fixing 3 bugs, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-08-04 16:00
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-07-09 Last update: 2026-07-09 22:48
testing migrations
  • This package will soon be part of the auto-onnxruntime transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-07-11] pipewire 1.6.8-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-09] Accepted pipewire 1.6.8-1 (source) into unstable (Dylan Aïssi)
  • [2026-06-26] pipewire 1.6.7-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-23] Accepted pipewire 1.6.7-1 (source) into unstable (Dylan Aïssi)
  • [2026-05-30] pipewire 1.6.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-27] Accepted pipewire 1.6.6-1 (source) into unstable (Dylan Aïssi)
  • [2026-05-25] pipewire 1.6.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-19] Accepted pipewire 1.4.9-1~bpo13+2 (source) into stable-backports (Loïc Minier) (signed by: Dylan Aïssi)
  • [2026-05-13] Accepted pipewire 1.6.5-1 (source) into unstable (Dylan Aïssi)
  • [2026-04-25] pipewire 1.6.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-23] Accepted pipewire 1.6.4-1 (source) into unstable (Dylan Aïssi)
  • [2026-04-13] pipewire 1.6.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-09] Accepted pipewire 1.6.3-1 (source) into unstable (Dylan Aïssi)
  • [2026-03-20] pipewire 1.6.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-17] Accepted pipewire 1.6.2-1 (source) into unstable (Dylan Aïssi)
  • [2026-03-09] Accepted pipewire 1.6.1-1 (source) into unstable (Dylan Aïssi)
  • [2026-02-19] Accepted pipewire 1.6.0-1 (source) into experimental (Dylan Aïssi)
  • [2026-01-21] pipewire 1.4.10-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-19] Accepted pipewire 1.5.85-1 (source) into experimental (Dylan Aïssi)
  • [2026-01-19] Accepted pipewire 1.4.10-1 (source) into unstable (Dylan Aïssi)
  • [2025-12-01] Accepted pipewire 1.5.84-1 (source) into experimental (Dylan Aïssi)
  • [2025-11-06] Accepted pipewire 1.5.83-1 (source) into experimental (Dylan Aïssi)
  • [2025-10-16] Accepted pipewire 1.5.81-1 (source) into experimental (Dylan Aïssi)
  • [2025-10-14] Accepted pipewire 1.4.9-1~bpo13+1 (source) into stable-backports (Dylan Aïssi)
  • [2025-10-12] pipewire 1.4.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-09] Accepted pipewire 1.4.9-1 (source) into unstable (Dylan Aïssi)
  • [2025-09-18] pipewire 1.4.8-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-11] Accepted pipewire 1.4.8-1 (source) into unstable (Dylan Aïssi)
  • [2025-09-06] Accepted pipewire 1.4.7-3~bpo13+1 (source amd64 all) into stable-backports (Debian FTP Masters) (signed by: Dylan Aïssi)
  • [2025-08-18] pipewire 1.4.7-3 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 79
  • RC: 0
  • I&N: 69
  • M&W: 10
  • F&P: 0
  • patch: 3
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 76)
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.6.4-1ubuntu1
  • patches for 1.6.4-1ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing