A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5557.json"