logo

CD-indexing cue files are the core of a serious Linux remote code exploit

ID: 615e17e9-9758-5282-a8f7-ca0d44e3b499

STIX ID: report--615e17e9-9758-5282-a8f7-ca0d44e3b499

Feed Name: Ars Technica Security

Threat Score
60/100

Date Published: 2023-10-11

Date Updated: 2026-04-19

Author: Kevin Purdy

...
...

The write-up explains CVE-2023-43641: an out-of-bounds array write in libcue that can be triggered via a malicious .cue file and lead to one-click code execution on GNOME desktops because the tracker miner auto-indexes user files. GitHub rates it 8.8 (High); upstream fixes exist but distributions need to deploy updated desktop packages. A benign test .cue is public, but the full PoC has not been released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.