Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-43641

37
FAUCET Score

CVE-2023-43641 is a critical out-of-bounds array access vulnerability in libcue versions 2.2.1 and earlier, primarily affecting GNOME desktop environments and various Linux distributions. This flaw allows for remote code execution (RCE) with a single click, as a malicious CUE sheet downloaded to ~/Downloads is automatically parsed by tracker-miners. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, the vulnerability presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there is no public exploit code or active exploitation reported, the vulnerability has garnered substantial community discussion and media coverage, highlighting its potential for widespread impact.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.0CPE matchmatch criteria
cpe:2.3:a:lipnitsk:libcue:*:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
16.57%
Probability of exploitation in next 30 days
EPSS Percentile
96.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1657 is in the 97th percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2023-43641Important

libcue: out-of-bounds array access leads to RCE

Oct 9, 2023

References

packetstormsecurity.com / files/176128/libcue-2.2.1-Out-Of-Bounds-Access.html
github.blog / 2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641
ExploitThird Party Advisory
github.com / lipnitsk/libcue/commit/cfb98a060fd79dbc3463d85f0f29c3c335dfa0ea
Patch
github.com / lipnitsk/libcue/commit/fdf72c8bded8d24cfa0608b8e97f2eed210a920e
Patch
github.com / lipnitsk/libcue/security/advisories/GHSA-5982-x7hv-r9cj
Exploit
lists.debian.org / debian-lts-announce/2023/10/msg00018.html
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/57JEYTRFG4PVGZZ7HIEFTX5I7OONFFMI
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/PGQOMFDBXGM3DOICCXKCUS76OTKTSPMN
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/XUS4HTNGGGUIFLYSKTODCRIOXLX5HGV3
Mailing List
debian.org / security/2023/dsa-5524
Third Party Advisory