Описание
Security update for tracker
This update for tracker fixes the following issues:
- CVE-2026-1765: heap buffer overflow vulnerability in
extract_txxx_tags(bsc#1257607). - CVE-2026-1766: heap buffer overflow vulnerability in
get_id3v23_tags(bsc#1257608).
Список пакетов
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Ссылки
- Link for SUSE-SU-2026:2713-1
- E-Mail link for SUSE-SU-2026:2713-1
- SUSE Security Ratings
- SUSE Bug 1257607
- SUSE Bug 1257608
- SUSE CVE CVE-2026-1765 page
- SUSE CVE CVE-2026-1766 page
Описание
A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.
Затронутые продукты
Ссылки
- CVE-2026-1765
- SUSE Bug 1257607
Описание
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by providing a malicious MP3 file, leading to a denial of service (DoS), which causes an application crash, and potentially disclosing sensitive information from the heap memory.
Затронутые продукты
Ссылки
- CVE-2026-1766
- SUSE Bug 1257608