CVE-2022-4964
Publication date 23 January 2024
Last updated 26 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Ubuntu’s pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
Status
Package | Ubuntu Release | Status |
---|---|---|
pipewire | 25.04 plucky |
Not affected
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy | Ignored see notes | |
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic | Ignored end of standard support | |
16.04 LTS xenial | Ignored end of standard support | |
14.04 LTS trusty | Ignored end of standard support | |
wireplumber | 25.04 plucky |
Not affected
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy | Ignored see notes | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Ignored end of standard support | |
16.04 LTS xenial | Ignored end of standard support | |
14.04 LTS trusty | Ignored end of standard support |
Notes
eslerm
jammy uses pulseaudio by default, but affected if switched
alexmurray
pipewire in focal does not include pipewire-pulse and so is not affected
hlibk
In order for the packages to be vulnerable in jammy, the user must have removed the default pulseaudio installation and switched to using pipewire-pulse. Additionally, the fix would require new dependencies as well as the addition of a new feature. This might break existing functionality.
Patch details
Package | Patch details |
---|---|
pipewire | |
wireplumber |
Severity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |