Hi Dylan,

On Thu, Sep 17, 2026 at 03:27:49PM +0200, Dylan Aïssi wrote:
> Hi,
> 
> By looking at the Red Hat package [1], CVE-2026-5674 seems to be fixed
> by several commits:
> - 6bc07dfe: only dlopen from the defined search paths
> - 821b62da: dlopen: improve prefix check some more
> - 8be0d753: dlopen: support search path ending in /
> - 0b117921: filter-graph: error when there are no valid nodes
> - aae60d8d: filter-graph: relax LADSPA plugin loading
> 
> All these commits landed in the branch 1.6 in April/May before the
> release 1.6.6.
> This is still to be confirmed, but I'd say CVE-2026-5674 is fixed since 1.6.6.
> 
> [1] 
> https://gitlab.com/redhat/centos-stream/rpms/pipewire/-/commit/bebe5357bc8faee5dd22317b0e1ce624f7ce1a16

Looks it make sense. Are you able to reach out to upstream to make
sure this is the set needed, we would make sure we will correctly
track the isseu. But it maps now to what Red Hat has picked up for
their updates.

Regards,
Salvatore

Reply via email to