CVE-2026-1765
Publication date 3 February 2026
Last updated 26 June 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| localsearch | 26.04 LTS resolute |
Not affected
|
| 25.10 questing | Not in release | |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| tracker-miners | 26.04 LTS resolute | Not in release |
| 25.10 questing |
Fixed 3.8.2-4ubuntu2.1
|
|
| 24.04 LTS noble |
Fixed 3.7.1-1ubuntu0.1
|
|
| 22.04 LTS jammy |
Fixed 3.3.3-0ubuntu0.20.04.4
|
|
| 20.04 LTS focal |
Vulnerable
|
|
| 18.04 LTS bionic |
Vulnerable
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.6 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-8019-1
- tracker-miners vulnerabilities
- 5 February 2026