CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8640-1: Engrampa vulnerability

unknownCVE-2023-52138
It was discovered that Engrampa incorrectly handled symbolic links when extracting certain archives. An attacker could possibly use this issue to write arbitrary files and execute arbitrary code.

CSIRTS triage

What
Engrampa incorrectly handles symbolic links during archive extraction, allowing arbitrary file writes and code execution.
Who is affected
Users extracting untrusted archives with Engrampa are affected.
Urgency
Moderate priority; no active exploitation confirmed but arbitrary code execution is possible.
Action
Upgrade Engrampa to a patched version that properly validates symbolic links.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Engrampa

Get an email when a new Engrampa advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-17
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8640-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2023-52138coverage & exploitation statusNVD · CVE.org

More from Ubuntu Security Notices