High severity7.5NVD Advisory· Published Oct 13, 2023· Updated Jun 17, 2026
CVE-2023-5557
CVE-2023-5557
Description
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20cpe:/a:redhat:enterprise_linux:8::appstream+ 4 more
- cpe:/a:redhat:enterprise_linux:8::appstreamrange: 0:2.1.5-2.el8_9.1
- cpe:/a:redhat:enterprise_linux:9::appstreamrange: 0:3.1.2-4.el9_3
- cpe:/o:redhat:enterprise_linux:7
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:/a:redhat:rhel_aus:8.4::appstream+ 1 more
- cpe:/a:redhat:rhel_aus:8.4::appstreamrange: 0:2.1.5-2.el8_4.1
- cpe:/a:redhat:rhel_e4s:8.2::appstreamrange: 0:2.1.5-2.el8_2.1
- Red Hat/Red Hat Enterprise Linux 8.6 Extended Update Supportv5cpe:/a:redhat:rhel_eus:8.6::appstreamRange: 0:2.1.5-2.el8_6.1
- Red Hat/Red Hat Enterprise Linux 8.8 Extended Update Supportv5cpe:/a:redhat:rhel_eus:8.8::appstreamRange: 0:2.1.5-2.el8_8.1
- Red Hat/Red Hat Enterprise Linux 9.0 Extended Update Supportv5cpe:/a:redhat:rhel_eus:9.0::appstreamRange: 0:3.1.2-2.el9_0
- Red Hat/Red Hat Enterprise Linux 9.2 Extended Update Supportv5cpe:/a:redhat:rhel_eus:9.2::appstreamRange: 0:3.1.2-4.el9_2
- osv-coords7 versionspkg:rpm/almalinux/tracker-minerspkg:rpm/opensuse/tracker-miners&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/tracker-miners&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/tracker-miners&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4pkg:rpm/suse/tracker-miners&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5pkg:rpm/suse/tracker-miners&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4pkg:rpm/suse/tracker-miners&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5
< 3.1.2-4.el9_3+ 6 more
- (no CPE)range: < 3.1.2-4.el9_3
- (no CPE)range: < 3.2.2-150400.3.7.1
- (no CPE)range: < 3.2.2-150400.3.7.1
- (no CPE)range: < 3.2.2-150400.3.7.1
- (no CPE)range: < 3.2.2-150400.3.7.1
- (no CPE)range: < 3.2.2-150400.3.7.1
- (no CPE)range: < 3.2.2-150400.3.7.1
Patches
Vulnerability mechanics
References
10- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- access.redhat.com/security/cve/CVE-2023-5557nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2023:7712nvd
- access.redhat.com/errata/RHSA-2023:7713nvd
- access.redhat.com/errata/RHSA-2023:7730nvd
- access.redhat.com/errata/RHSA-2023:7731nvd
- access.redhat.com/errata/RHSA-2023:7732nvd
- access.redhat.com/errata/RHSA-2023:7733nvd
- access.redhat.com/errata/RHSA-2023:7739nvd
- access.redhat.com/errata/RHSA-2023:7744nvd
News mentions
0No linked articles in our index yet.