Executive brief
A security vulnerability has been identified in GNOME localsearch (formerly tracker-miners), a system service used to index and search files on Linux desktops. The flaw exists in the component that extracts metadata from MP3 files. If a user downloads or saves a specially crafted malicious MP3 file, the indexing service may crash or potentially allow unauthorized access to sensitive information stored in the system's memory.
Technical details
A heap buffer overflow (specifically an out-of-bounds read) exists in the `extract_txxx_tags` function within `src/extractor/tracker-extract-mp3.c`. The vulnerability is triggered when parsing User Defined Text Information Frames (TXXX) in ID3v2 tags. The code fails to validate if a calculated offset exceeds the total frame size (`csize`) before advancing the data pointer. This leads to an integer underflow during length calculation for `g_convert`, resulting in a very large length value being passed to memory-reading functions. An attacker can exploit this by providing a malicious MP3 file, causing a SIGSEGV (Denial of Service) or potentially leaking heap memory contents.
Affected products
- GNOME localsearch unspecified
- GNOME tracker-miners unspecified
Timeline
- 2026-02-02: other: Vulnerability reported to Red Hat Bugzilla
- 2026-06-16: disclosed: CVE published to NVD