CVE-2026-1767

Publication date 3 February 2026

Last updated 25 June 2026


Ubuntu priority

Cvss 3 Severity Score

5.6 · Medium

Score breakdown

Description

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.

Status

Package Ubuntu Release Status
localsearch 25.10 questing Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
tracker-miners 25.10 questing
Fixed 3.8.2-4ubuntu2.1
24.04 LTS noble
Fixed 3.7.1-1ubuntu0.1
22.04 LTS jammy
Fixed 3.3.3-0ubuntu0.20.04.4
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
localsearch
tracker-miners

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.6 · Medium

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-8019-1
    • tracker-miners vulnerabilities
    • 5 February 2026

Other references


Access our resources on patching vulnerabilities