CVE-2026-1766
EUVD-2026-3702716.06.2026, 02:16
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by providing a malicious MP3 file, leading to a denial of service (DoS), which causes an application crash, and potentially disclosing sensitive information from the heap memory.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnome | localsearch | - |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||
|---|---|---|---|---|---|---|---|
| tracker-miner-files |
| ||||||
| tracker-miners |
|
Amazon Linux Releases
Common Weakness Enumeration