CVE-2026-1767
Publication date 3 February 2026
Last updated 25 June 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| localsearch | 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| tracker-miners | 25.10 questing |
Fixed 3.8.2-4ubuntu2.1
|
| 24.04 LTS noble |
Fixed 3.7.1-1ubuntu0.1
|
|
| 22.04 LTS jammy |
Fixed 3.3.3-0ubuntu0.20.04.4
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.6 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-8019-1
- tracker-miners vulnerabilities
- 5 February 2026