Junglewise Threat Intelligence

CVE-2026-1765: GNOME localsearch heap buffer overflow in tracker-extract-mp3

CVE-2026-1765 · Severity: medium · CVSS 5.6 · Published 2026-06-16

Technologies: Gnome Localsearch. Vendors: Gnome.

Executive brief

A security vulnerability has been identified in GNOME localsearch (formerly tracker-miners), a system service used to index and search files on Linux desktops. The flaw exists in the component that extracts metadata from MP3 files. If a user downloads or saves a specially crafted malicious MP3 file, the indexing service may crash or potentially allow unauthorized access to sensitive information stored in the system's memory.

Technical details

A heap buffer overflow (specifically an out-of-bounds read) exists in the `extract_txxx_tags` function within `src/extractor/tracker-extract-mp3.c`. The vulnerability is triggered when parsing User Defined Text Information Frames (TXXX) in ID3v2 tags. The code fails to validate if a calculated offset exceeds the total frame size (`csize`) before advancing the data pointer. This leads to an integer underflow during length calculation for `g_convert`, resulting in a very large length value being passed to memory-reading functions. An attacker can exploit this by providing a malicious MP3 file, causing a SIGSEGV (Denial of Service) or potentially leaking heap memory contents.

Affected products

  • GNOME localsearch unspecified
  • GNOME tracker-miners unspecified

Timeline

  • 2026-02-02: other: Vulnerability reported to Red Hat Bugzilla
  • 2026-06-16: disclosed: CVE published to NVD

References

Related threats