CVE-2026-1764
published 2026-06-16CVE-2026-1764: A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags…
PriorityP424medium5.6CVSS 3.1
AVLACLPRLUIRSUCLINAH
EPSS
0.21%
11.1th percentile
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by triggering a read of unmapped memory. In some cases, it could also lead to information disclosure by reading visible heap data.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | localsearch | < localsearch 3.8.2-12 (forky) | localsearch 3.8.2-12 (forky) |
| debian | tracker-miners | < localsearch 3.8.2-12 (forky) | localsearch 3.8.2-12 (forky) |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor.
ghsa_unreviewed·2026-06-16
CVE-2026-1764 [MEDIUM] CWE-125 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor.
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by triggering a read of unmapped memory. In some cases, it could also lead to information disclosure by reading visible heap data.
OSV
CVE-2026-1764: [Heap Buffer Overflow in GNOME localsearch MP3 Extractor]
osv·2026-02-03
CVE-2026-1764 CVE-2026-1764: [Heap Buffer Overflow in GNOME localsearch MP3 Extractor]
[Heap Buffer Overflow in GNOME localsearch MP3 Extractor]
Ubuntu
tracker-miners vulnerabilities
vendor_ubuntu·2026-02-05
CVE-2026-1764 tracker-miners vulnerabilities
Title: tracker-miners vulnerabilities
Summary: tracker-miners could be made to crash or run programs as your login if it
opened a specially crafted file.
Fatih Çelik discovered that tracker-miners incorrectly handled certain
malformed MP3 files. An attacker could use this issue to cause
tracker-miners to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files
vendor_redhat·2026-02-02·CVSS 5.6
CVE-2026-1764 [MEDIUM] CWE-125 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files
localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by triggering a read of unmapped memory. In some cases, it could also lead to information disclosure by reading visible heap data.
Statement: This vulnerability has MODERATE impact. A heap buffer overflow in `tracker-extract-mp3` can occur when parsing specially crafted MP3 files containing ID3v2.4
Debian
CVE-2026-1764: localsearch
vendor_debian·2026
CVE-2026-1764 CVE-2026-1764: localsearch
forky: resolved (fixed in 3.8.2-12)
sid: resolved (fixed in 3.8.2-12)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-46247 kernel: clk: qcom: gfx3d: add parent to parent request map
bugzilla·2026-06-03
CVE-2026-46247 [LOW] CVE-2026-46247 kernel: clk: qcom: gfx3d: add parent to parent request map
CVE-2026-46247 kernel: clk: qcom: gfx3d: add parent to parent request map
In the Linux kernel, the following vulnerability has been resolved:
clk: qcom: gfx3d: add parent to parent request map
After commit d228ece36345 ("clk: divider: remove round_rate() in favor
of determine_rate()") determining GFX3D clock rate crashes, because the
passed parent map doesn't provide the expected best_parent_hw clock
(with the roundd_rate path before the offending commit the
best_parent_hw was ignored).
Set the field in parent_req in addition to setting it in the req,
fixing the crash.
clk_hw_round_rate (drivers/clk/clk.c:1764) (P)
clk_divider_bestdiv (drivers/clk/clk-divider.c:336)
divider_determine_rate (drivers/clk/clk-divider.c:358)
clk_alpha_pll_postdiv_determine_rate (drivers/clk/qcom/clk-alpha-
Bugzilla
CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
bugzilla·2026-02-03
CVE-2026-1764 [MEDIUM] CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Bug reports for this component on Red Hat Bugzilla are not actively monitored. Please consider reporting your issue directly to GNOME at https://gitlab.gnome.org/GNOME/ to improve the chances that your issue will be resolved. This issue should only be kept open if it:
1. Relates to Fedora packaging or integration with other Fedora components
2. Is required for Fedora release processes, such as blocker bugs and freeze exceptions
If this issue isn't needed fo
Bugzilla
CVE-2026-1764 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files
bugzilla·2026-02-02·CVSS 5.6
CVE-2026-1764 [MEDIUM] CVE-2026-1764 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files
CVE-2026-1764 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files
Vulnerability Report: Heap Buffer Overflow in GNOME localsearch MP3 Extractor
Project: https://gitlab.gnome.org/GNOME/localsearch
Component: tracker-extract-mp3
Vulnerability Type: Heap Buffer Overflow (Read)
Description
A secondary heap buffer overflow vulnerability exists in the extract_performers_tags function of src/extractor/tracker-extract-mp3.c. When parsing ID3v2.4 tags, a missing bounds check allows the loop to advance pos + offset beyond the buffer size (csize). This causes the remaining length calculation to underflow, effectively passing a negative value (interpreted as -1) to g_convert. This triggers g_co
Wiz
CVE-2026-1764 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-1764 [MEDIUM] CVE-2026-1764 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1764 :
Linux Debian vulnerability analysis and mitigation
[Heap Buffer Overflow in GNOME localsearch MP3 Extractor]
Source : NVD
Published February 3, 2026
CNA Score N/A
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
localsearch-debuginfo
localsearch-debugsource
Sources
NVD
Debian 11 No Fix Added at: Feb 04, 2026
Debian 12, 13 Severity MEDIUM No Fix Added at: Feb 04, 2026
Debian 14 Has Fix Added at: Feb 04, 2026
Echo No Fix Added at: Feb 04, 2026
Red Hat 8, 9, 10 Severity MEDIUM No Fix Added at: Feb 04, 2026
Ubuntu 18.04, 20.04 Severity MEDIUM No
2026-06-16
Published