📖 ~4 min read • Source: SUSE advisory SUSE-SU-2023:4868-1 (see also SUSE bugzilla)
Related CVEs: CVE-2023-5557
Upstream summary: A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
Table of contents
Symptom & Impact
On openSUSE Tumbleweed hosts running tracker-miners, the vulnerable code is started by something else – a web or application server, or an on-demand supervisor such as inetd, xinetd or a systemd socket unit – rather than by a service of its own. Patching replaces the files on disk immediately, but a long-running parent that has already loaded them (PHP-FPM workers, an application server, a persistent worker pool) keeps serving the old code until it is recycled. Connection-per-process supervisors pick the fix up on the next connection, so the exposure window differs sharply between the two and is worth confirming rather than assuming. tracker-miners is started by a hosting server or an on-demand supervisor rather than by a unit of its own, so restart whatever launches it – not tracker-miners.
Environment & Reproduction
Reproduction targets openSUSE Tumbleweed. Confirm release and installed package:
cat /etc/os-release
rpm -q tracker-miners
zypper info tracker-miners | head -20
zypper lr -E # enabled repositories
Exercise the workload that uses tracker-miners while collecting:
sudo zypper ps # NATIVE SUSE TOOL, no extra package: every running process still using deleted/replaced files, plus the owning service name
sudo zypper ps -s # short table (PID, PPID, UID, login, command, service) without the per-file detail
sudo zypper ps -sss # service names ONLY, one per line - safe to pipe straight into systemctl
sudo journalctl -xe --no-pager | tail -200
sudo tail -200 /var/log/zypp/history
sudo journalctl -k | grep -i apparmor | tail -100
# Bundle evidence for SUSE / community support:
sudo supportconfig -R /var/tmp -B tracker-miners
Root Cause Analysis
Root cause is documented in SUSE advisory SUSE-SU-2023:4868-1. openSUSE security maintainers shipped fixes in the corresponding tracker-miners update for openSUSE Tumbleweed; running an outdated build leaves the host exposed to the failure modes described in the advisory. Correlate zypper history with system logs:
sudo zypper history | grep tracker-miners
sudo zypper history --since='-7 days' | tail -40
sudo journalctl -k | grep -i apparmor | tail -100
cat /proc/sys/kernel/tainted # non-zero = tainted kernel / out-of-tree modules
snapper list | tail -20 # snapshots taken around each zypper transaction
Quick Triage
Run these on openSUSE Tumbleweed to capture the current state of tracker-miners:
rpm -q tracker-miners # installed NVR
rpm -V tracker-miners # verify shipped files
sudo zypper ref # refresh repos
sudo zypper dup --dry-run # pending rolling updates
systemctl --failed --no-pager
sudo firewall-cmd --list-all
sudo aa-status # AppArmor profiles
rpm -ql tracker-miners | grep -E '^/(usr/lib|etc)/systemd/(system|user)/[^/]+\.(service|socket|timer|path|target|mount)$' # the units tracker-miners REALLY ships - NO OUTPUT means it ships no service at all, so never run systemctl on it
rpm -ql tracker-miners | grep -E '^/usr/sbin/rc[^/]+$' # SUSE-only rcNAME compat symlink (it points at /usr/sbin/service, not at a unit): the NAME after 'rc' IS the service name - bind ships /usr/sbin/rcnamed, so the unit is named.service
Step-by-Step Diagnosis
-
List failed systemd units.
systemctl --failed --no-pager -
Tail the journal for
tracker-minersand the system bus.sudo journalctl -xe -f --no-pager -
Inspect firewall posture (firewalld is the default on openSUSE).
sudo firewall-cmd --list-all-zones --permanent sudo nft list ruleset 2>/dev/null | head -50 -
Surface AppArmor denials and switch the profile to complain mode if needed.
sudo journalctl -k | grep -i 'apparmor="DENIED"' | tail -30 sudo aa-status -
Verify
tracker-minersintegrity and reinstall if anything is altered.sudo rpm -V tracker-miners sudo zypper verify sudo zypper install --force tracker-miners -
Inspect Snapper snapshots to know exactly which transaction introduced the regression.
sudo snapper list | tail -20 sudo snapper status <pre-id>..<post-id> -
Correlate findings with
/var/log/zypp/history,zypper history, and SUSE advisory SUSE-SU-2023:4868-1 to pin the change that introduced the regression.
Solution – Primary Fix
Apply the corrective zypper transaction referenced by SUSE advisory SUSE-SU-2023:4868-1, then reload affected systemd units:
sudo zypper ref # refresh repos
# Tumbleweed is a rolling release — use 'dup', not 'patch':
sudo zypper dup --no-allow-vendor-change # rolling distribution upgrade
# To target only the affected package while still on rolling:
sudo zypper dup --no-allow-vendor-change tracker-miners
sudo systemctl daemon-reload
# Unit name may differ from pkg name; check first:
sudo systemctl daemon-reload # load unit files replaced by the update; this alone restarts nothing
sudo systemctl restart UNIT1.service UNIT2.service # restart several in ONE transaction - systemd applies their own After=/Before= ordering, so low-level units (dbus, database, broker) go before their consumers
sudo systemctl restart UNIT.service # NOTE: 'systemctl reload' is NOT enough after a library patch - the process must re-exec to map the new .so
sudo systemctl reload apparmor.service # only if 'rpm -ql tracker-miners | grep /etc/apparmor.d/' showed the package ships AppArmor profiles
rpm -q tracker-miners # confirm new NVR
For kernel / glibc / systemd / openssl rolls a reboot is required. Tumbleweed does not ship Live Patching, so plan a maintenance window or use Snapper to roll back if a regression appears:
sudo zypper ps -s # services using deleted libs
sudo snapper list | tail -5 # confirm pre/post snapshots exist
sudo systemctl reboot # or: sudo shutdown -r now
Need help rolling this patch across an openSUSE fleet? Our IT Solutions & Services team supports openSUSE Leap and Tumbleweed estates with snapper-backed rollback workflows and salt-driven patching. Get in touch for a free consultation.
Solution – Alternative Approaches
If the primary fix is not viable, choose from these:
-
Roll back via Snapper (Btrfs snapshots are taken automatically before zypper transactions on openSUSE Tumbleweed). This is the primary safety net for openSUSE administrators:
sudo snapper list sudo snapper status <pre-id>..<post-id> # diff between two snapshot numbers sudo snapper undochange <pre-id>..<post-id> sudo snapper rollback <pre-id> # boot the host into the chosen snapshot sudo systemctl reboot -
Lock the package so zypper cannot upgrade it:
sudo zypper al tracker-miners # add lock zypper ll | grep tracker-miners # list locks sudo zypper rl tracker-miners # remove lock -
Install an older NVR if a regression is suspected:
zypper se -s tracker-miners # show all available versions sudo zypper install --oldpackage tracker-miners-<older-NVR> -
Disable the AppArmor profile briefly to confirm policy is the cause, then re-enable:
# reproduce, capture denials in the journal: sudo journalctl -k | grep apparmor | tail -
Pin Tumbleweed to a known-good snapshot from the openSUSE history server while you investigate. This keeps the rolling release reproducible across a fleet:
# Edit /etc/zypp/repos.d/repo-oss.repo and point baseurl at # http://download.opensuse.org/history/<YYYYMMDD>/tumbleweed/repo/oss/ sudo zypper ref sudo zypper dup --no-allow-vendor-change
Verification & Acceptance Criteria
All of these should pass after the fix:
rpm -q tracker-miners # expected fixed NVR
sudo zypper dup --dry-run # no pending rolls expected
sudo firewall-cmd --list-services
sudo aa-status | head -5
sudo zypper ps -s # any services still using deleted libs
The conditions described in the advisory must no longer be reported for tracker-miners across two consecutive runs.
Rollback Plan
Capture state before any change. On openSUSE, Snapper is the canonical rollback path:
rpm -qa > /root/rpm-pre.txt
sudo zypper history list > /root/zypper-history-pre.txt
# Snapper takes pre/post snapshots automatically on Btrfs root.
sudo snapper create -d 'pre-patch-tracker-miners' # explicit named snapshot
sudo snapper list | head
To revert if the patch / roll is bad:
# Preferred on Btrfs root — boot the prior snapshot:
sudo snapper list
sudo snapper rollback <pre-id>
sudo systemctl reboot
# Or downgrade just the package:
sudo zypper install --oldpackage tracker-miners-<older-NVR>
sudo systemctl daemon-reload
# Custom AppArmor profile cleanup:
Prevention & Hardening
Reduce the chance of this recurring on openSUSE Tumbleweed:
-
Run rolling upgrades on a schedule — Tumbleweed receives a snapshot most weekdays. Stagger across the fleet so any regression is caught early:
sudo zypper ref sudo zypper dup --no-allow-vendor-change # Optional: drive from salt/ansible with a maintenance window per host group. -
Subscribe to opensuse-security-announce and watch suse.com/support/update.
-
Lock sensitive packages so they cannot be auto-upgraded:
sudo zypper al tracker-miners -
Ensure Snapper is enabled on the root subvolume and pre/post hooks run for every zypper transaction. This is the cornerstone of safe openSUSE patching:
sudo snapper -c root get-config | head # Default zypper plugin: /usr/lib/zypp/plugins/commit/snapper.zypp-commit-plugin sudo snapper list | tail -10 -
Monitor file integrity with AIDE:
sudo zypper install -y aide sudo aide --init && sudo mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db sudo aide --check -
Keep AppArmor profiles in enforce; review
/etc/apparmor.d/after every package upgrade. -
Apply CIS / openSUSE hardening guidance and use salt or ansible to enforce baseline state across the fleet.
Related Errors & Cross-Refs
Issues that commonly surface alongside a tracker-miners update: zypper lock contention, systemd unit ordering cycles, AppArmor denials, firewalld zone drift, and kernel taint flags. Useful triage:
sudo zypper ps -s
systemd-analyze critical-chain
sudo journalctl -k | grep apparmor | tail
sudo firewall-cmd --get-active-zones
cat /proc/sys/kernel/tainted
sudo snapper list | tail
View all opensuse-tumbleweed tutorials on the Tutorials Hub →
Browse all common problems & solutions on the Tutorials Hub.
References & Further Reading
Primary reference: SUSE advisory SUSE-SU-2023:4868-1 (see also SUSE bugzilla). Manual pages useful on openSUSE Tumbleweed:
man zypper
man zypper.conf
man systemctl
man journalctl
man firewall-cmd
man snapper
man apparmor
man aa-status
Other resources: openSUSE documentation, suse.com/security, openSUSE security portal, and per-package notes in /usr/share/doc/packages/tracker-miners/ for components implicated in this advisory.
View all openSUSE Tumbleweed tutorials on the Tutorials Hub →