rootpwn

critical · CVSS v3 9.1

CVE-2026-97029

Flatpak’s process ID namespace separation fails to isolate kill(0, signal) and killpg(0, signal) calls, allowing a sandboxed app to terminat

Overview

Flatpak’s process ID namespace separation fails to isolate kill(0, signal) and killpg(0, signal) calls, allowing a sandboxed app to terminate processes outside its sandbox that share the same process group. This flaw can be exploited to disrupt desktop shells and other system processes, leading to a denial‑of‑service condition. The vulnerability is rated critical with a CVSS v3 score of 9.1.

Description

Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.

Impact

The vulnerability compromises Availability by enabling a sandboxed application to terminate unrelated system processes, potentially crashing the desktop shell and disrupting user sessions. While Confidentiality and Integrity are not directly affected, the resulting service interruption can expose users to further attacks if the system becomes unstable.

Remediation

1. Update Flatpak to the latest patched version (≥1.14.0) which enforces proper process group isolation. 2. Verify that kill(0, signal) and killpg(0, signal) are blocked for sandboxed apps by checking the Flatpak security policy. 3. If immediate patching is not possible, isolate sandboxed apps into separate process groups using systemd or flatpak‑override commands to prevent shared group access. 4. Monitor system logs for unexpected kill signals originating from sandboxed applications.

Risk context

The CVE is classified as critical with a CVSS v3 score of 9.1, indicating a high likelihood of severe impact if exploited. Defenders should treat this as an urgent priority, especially on systems running desktop environments that may share process groups with Flatpak applications.

Affected products

  • Flatpak
  • Flatpak runtime
  • Flatpak sandboxed apps

Scores

Severity
critical
CVSS v2
6.8
CVSS v3
9.1
CVSS v4
—
EPSS
—

Flatpak sandbox process group kill denial of service critical desktop shell process isolation

← All CVEs