An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-nautilus | Aug 22, 2024 | Apr 22, 2019 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Apr 22, 2019 | |
| Debian | debian-upgrade-nautilus | Jul 30, 2024 | Apr 22, 2019 | |
| Gentoo Linux | gentoo-linux-upgrade-gnome-base-nautilus | Sep 3, 2019 | Apr 22, 2019 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-nautilushuawei-euleros-2_0_sp8-upgrade-nautilus-extensions | Mar 29, 2022 | Apr 22, 2019 | |
| Suse | — | suse-upgrade-flatpaksuse-upgrade-flatpak-develsuse-upgrade-gnome-shell-search-provider-nautilussuse-upgrade-libflatpak0suse-upgrade-libnautilus-extension1suse-upgrade-nautilussuse-upgrade-nautilus-develsuse-upgrade-nautilus-langsuse-upgrade-typelib-1_0-flatpak-1_0suse-upgrade-typelib-1_0-nautilus-3_0 | Sep 3, 2019 | Apr 22, 2019 |
| Ubuntu | ubuntu-upgrade-nautilus | Nov 19, 2024 | Apr 22, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub