Flatpak · Flatpak · CVE-2026-97029
**Name of the Vulnerable Software and Affected Versions**
Flatpak (affected versions not specified)
**Description**
Process ID namespace separation fails to prevent sandboxed applications from sending signals to processes outside the sandbox that share the same process group. A compromised or malicious application can utilize the `kill(0, signal)` or `killpg(0, signal)` functions to terminate external processes, such as the desktop shell, resulting in a denial of service.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.