Executive brief
A vulnerability exists in the GNOME localsearch tool, which is used by Linux systems to index and search for files. By tricking a user into downloading or opening a specially crafted MP3 file, an attacker can cause the file-indexing service to crash or potentially leak sensitive information from the system's memory. This affects the reliability of the desktop search function and poses a minor risk to data privacy.
Technical details
A heap buffer overflow (out-of-bounds read) exists in the `extract_performers_tags` function within `src/extractor/tracker-extract-mp3.c` of GNOME localsearch. The vulnerability is caused by an incorrect length calculation when parsing performer tags in MP3 files with malformed ID3 tags. Specifically, the code passes an incorrect remaining buffer size to the UTF-8 conversion functions, allowing `iconv` to read past the allocated memory. An attacker can exploit this by providing a crafted MP3 file, leading to a process crash (SIGSEGV) or the disclosure of sensitive heap data. The attack requires the user to interact with the file (e.g., downloading it to a monitored directory) so that the local indexing service attempts to extract its metadata.
Affected products
- GNOME localsearch (tracker-miners) unspecified
Timeline
- 2026-02-02: disclosed: Initial report in Red Hat Bugzilla
- 2026-06-16: advisory: CVE published to NVD