CVE-2026-1765
published 2026-06-16CVE-2026-1765: A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow…
PriorityP425medium5.6CVSS 3.1
AVLACLPRLUIRSUCLINAH
EPSS
0.14%
3.6th percentile
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | localsearch | < localsearch 3.8.2-12 (forky) | localsearch 3.8.2-12 (forky) |
| debian | tracker-miners | < localsearch 3.8.2-12 (forky) | localsearch 3.8.2-12 (forky) |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners).
ghsa_unreviewed·2026-06-16
CVE-2026-1765 [MEDIUM] CWE-125 A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners).
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.
OSV
CVE-2026-1765: [Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags)]
osv·2026-02-03
CVE-2026-1765 CVE-2026-1765: [Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags)]
[Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags)]
Ubuntu
tracker-miners vulnerabilities
vendor_ubuntu·2026-02-05
CVE-2026-1764 tracker-miners vulnerabilities
Title: tracker-miners vulnerabilities
Summary: tracker-miners could be made to crash or run programs as your login if it
opened a specially crafted file.
Fatih Çelik discovered that tracker-miners incorrectly handled certain
malformed MP3 files. An attacker could use this issue to cause
tracker-miners to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Denial of Service and potential information disclosure via crafted MP3 files
vendor_redhat·2026-02-02·CVSS 5.6
CVE-2026-1765 [MEDIUM] CWE-125 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Denial of Service and potential information disclosure via crafted MP3 files
localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Denial of Service and potential information disclosure via crafted MP3 files
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.
Statement: This vulnerability has MODERATE impact. A heap buffer overflow flaw in the `tracker-extract-mp3` component of GNOME localsearch can be triggered by processing a specially crafted MP3 file. This vulnerability could lead
Debian
CVE-2026-1765: localsearch
vendor_debian·2026
CVE-2026-1765 CVE-2026-1765: localsearch
forky: resolved (fixed in 3.8.2-12)
sid: resolved (fixed in 3.8.2-12)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-1765 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-1765 [MEDIUM] CVE-2026-1765 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1765 :
Linux Debian vulnerability analysis and mitigation
[Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags)]
Source : NVD
Published February 3, 2026
CNA Score N/A
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
localsearch-debuginfo
localsearch-debugsource
Sources
NVD
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Feb 04, 2026
Debian 14 Has Fix Added at: Feb 04, 2026
Echo No Fix Added at: Feb 04, 2026
Red Hat 8, 9, 10 Severity MEDIUM No Fix Added at: Feb 04, 2026
Ubuntu 18.04, 20.04 Severity MEDIUM No Fix Added at: Feb 20, 202
Bugzilla
CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation [fedora-all]
bugzilla·2026-06-30·CVSS 7.2
CVE-2026-11884 [HIGH] CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation [fedora-all]
CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Two heap buffer overflow vulnerabilities exist in 389 Directory Server schema serialization code. Both are incomplete-fix variants of CVE-2025-14905: the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat().
Variant 1 (read_schema_dse, schema.c:1765): triggered during schema DSE reads; overflow at SUP >
Bugzilla
CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation
bugzilla·2026-06-04·CVSS 7.2
CVE-2026-11884 [HIGH] CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation
CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation
Two heap buffer overflow vulnerabilities exist in 389 Directory Server schema serialization code. Both are incomplete-fix variants of CVE-2025-14905: the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat().
Variant 1 (read_schema_dse, schema.c:1765): triggered during schema DSE reads; overflow at SUP >= ~248 bytes.
Variant 2 (schema_oc_to_string, schema.c:5151): triggered during schema replication comparison; overflow at SUP >= ~62 bytes.
An attacker with Directory Manager privileges can crash the server. In replication topologies, a
Bugzilla
CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
bugzilla·2026-02-03
CVE-2026-1764 [MEDIUM] CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
CVE-2026-1764 CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 tracker-miners: various flaws [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Bug reports for this component on Red Hat Bugzilla are not actively monitored. Please consider reporting your issue directly to GNOME at https://gitlab.gnome.org/GNOME/ to improve the chances that your issue will be resolved. This issue should only be kept open if it:
1. Relates to Fedora packaging or integration with other Fedora components
2. Is required for Fedora release processes, such as blocker bugs and freeze exceptions
If this issue isn't needed fo
Bugzilla
CVE-2026-1765 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Denial of Service and potential information disclosure via crafted MP3 files
bugzilla·2026-02-02·CVSS 5.6
CVE-2026-1765 [MEDIUM] CVE-2026-1765 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Denial of Service and potential information disclosure via crafted MP3 files
CVE-2026-1765 localsearch: tracker-miners: GNOME localsearch MP3 Extractor: Denial of Service and potential information disclosure via crafted MP3 files
Vulnerability Report: Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags)
Project: https://gitlab.gnome.org/GNOME/localsearch
Component: tracker-extract-mp3
Vulnerability Type: Heap Buffer Overflow (Read)
Description
A heap buffer overflow vulnerability exists in the extract_txxx_tags function of src/extractor/tracker-extract-mp3.c. This function handles User Defined Text Information Frames (TXXX). When parsing these frames, the code calculates an offset based on the description string length but fails to verify if this offset exceeds the total frame size (csize) before using it to calculate the remaining buffer size for
2026-06-16
Published