Описание
Security update for tracker-miners
This update for tracker-miners fixes the following issues:
- CVE-2026-1764: heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files (bsc#1257606).
- CVE-2026-1765: denial of Service and potential information disclosure via crafted MP3 files (bsc#1257607).
- CVE-2026-1766: denial of Service and information disclosure via malformed MP3 files (bsc#1257608).
- CVE-2026-1767: heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags (bsc#1257609).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
SUSE Linux Enterprise Workstation Extension 15 SP7
openSUSE Leap 15.6
Ссылки
- Link for SUSE-SU-2026:0780-1
- E-Mail link for SUSE-SU-2026:0780-1
- SUSE Security Ratings
- SUSE Bug 1257606
- SUSE Bug 1257607
- SUSE Bug 1257608
- SUSE Bug 1257609
- SUSE CVE CVE-2026-1764 page
- SUSE CVE CVE-2026-1765 page
- SUSE CVE CVE-2026-1766 page
- SUSE CVE CVE-2026-1767 page
Описание
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by triggering a read of unmapped memory. In some cases, it could also lead to information disclosure by reading visible heap data.
Затронутые продукты
Ссылки
- CVE-2026-1764
- SUSE Bug 1257606
Описание
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.
Затронутые продукты
Ссылки
- CVE-2026-1765
- SUSE Bug 1257607
Описание
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by providing a malicious MP3 file, leading to a denial of service (DoS), which causes an application crash, and potentially disclosing sensitive information from the heap memory.
Затронутые продукты
Ссылки
- CVE-2026-1766
- SUSE Bug 1257608
Описание
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.
Затронутые продукты
Ссылки
- CVE-2026-1767
- SUSE Bug 1257609