Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves four vulnerabilities can now be installed.. # Security update for localsearch Announcement ID: SUSE-SU-2026:21854-1 Release Date: 2026-05-27T16:46:37Z Rating: moderate References: * bsc#1257606 * bsc#1257607 * bsc#1257608 * bsc#1257609 Cross-References: * CVE-2026-1764 * CVE-2026-1765 * CVE-2026-1766 * CVE-2026-1767 CVSS scores: * CVE-2026-1764 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-1764 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1765 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for localsearch fixes the following issues: * CVE-2026-1764: Fixed a heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files. (bsc#1257606) * CVE-2026-1765: Fixed a Denial of Service and potential information disclosure via crafted MP3 files. (bsc#1257607) * CVE-2026-1766: Fixed a Denial of Service and information disclosure via malformed MP3 files. (bsc#1257608) * CVE-2026-1767: Fixed a heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags. (bsc#1257609) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-809=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-809=1 ## Package List: * SUSE Linux EnterpriseServer 16.0 (aarch64 ppc64le s390x x86_64) * localsearch-debuginfo-3.8.2-160000.3.1 * localsearch-3.8.2-160000.3.1 * localsearch-debugsource-3.8.2-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * localsearch-lang-3.8.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * localsearch-debuginfo-3.8.2-160000.3.1 * localsearch-3.8.2-160000.3.1 * localsearch-debugsource-3.8.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * localsearch-lang-3.8.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1764.html * https://www.suse.com/security/cve/CVE-2026-1765.html * https://www.suse.com/security/cve/CVE-2026-1766.html * https://www.suse.com/security/cve/CVE-2026-1767.html * https://bugzilla.suse.com/show_bug.cgi?id=1257606 * https://bugzilla.suse.com/show_bug.cgi?id=1257607 * https://bugzilla.suse.com/show_bug.cgi?id=1257608 * https://bugzilla.suse.com/show_bug.cgi?id=1257609 . SUSE Linux Enterprise 16.0 offers a security update for localsearch addressing four vulnerabilities including denial of service.. SUSE Linux 16.0, security updates, localsearch, denial of service, information disclosure. . Severity: moderate. LinuxSecurity.com Team
An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.. openSUSE security update: security update for localsearch ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20821-1 Rating: moderate References: * bsc#1257606 * bsc#1257607 * bsc#1257608 * bsc#1257609 Cross-References: * CVE-2026-1764 * CVE-2026-1765 * CVE-2026-1766 * CVE-2026-1767 CVSS scores: * CVE-2026-1764 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1764 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-1765 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for localsearch fixes the following issues: - CVE-2026-1764: Fixed a heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files. (bsc#1257606) - CVE-2026-1765: Fixed a Denial of Service and potential information disclosure via crafted MP3 files. (bsc#1257607) - CVE-2026-1766: Fixed a Denial of Service and information disclosure via malformed MP3 files. (bsc#1257608) - CVE-2026-1767: Fixed a heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags. (bsc#1257609) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-809=1 Package List: - openSUSE Leap 16.0: localsearch-3.8.2-160000.3.1 localsearch-lang-3.8.2-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-1764.html * https://www.suse.com/security/cve/CVE-2026-1765.html * https://www.suse.com/security/cve/CVE-2026-1766.html * https://www.suse.com/security/cve/CVE-2026-1767.html . Critical openSUSE update for localsearch addressing multiple issues including denial of service and information disclosure risks.. openSUSE Localsearch Update DenialOfService InformationDisclosure. . Severity: moderate. LinuxSecurity.com Team
Add a patch for several CVEs: CVE-2026-1764 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor CVE-2026-1765 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags) CVE-2026-1766 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor (ID3v2.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ba6641558a 2026-03-23 01:07:08.010780+00:00 -------------------------------------------------------------------------------- Name : localsearch Product : Fedora 43 Version : 3.10.2 Release : 2.fc43 URL : https://gnome.pages.gitlab.gnome.org/localsearch/ Summary : Localsearch and metadata extractors Description : Tinysparql is a powerful desktop-neutral first class object database, tag/metadata database and search tool. This package contains various miners and metadata extractors for tinysparql. -------------------------------------------------------------------------------- Update Information: Add a patch for several CVEs: CVE-2026-1764 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor CVE-2026-1765 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags) CVE-2026-1766 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor (ID3v2.3 COMM Tags) CVE-2026-1767 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 19 2026 Milan Crha - 3.10.2-2 - Add patch for several CVE-s: - CVE-2026-1764 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor - CVE-2026-1765 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags) - CVE-2026-1766 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor (ID3v2.3 COMM Tags) - CVE-2026-1767 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor -------------------------------------------------------------------------------- References: [ 1 ] Bug #2435995 - CVE-2026-1764CVE-2026-1765 CVE-2026-1766 CVE-2026-1767 localsearch: various flaws [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2435995 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ba6641558a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 4 vulnerabilities can now be installed.. # localsearch-3.10.2-2.1 on GA media Announcement ID: openSUSE-SU-2026:10162-1 Rating: moderate Cross-References: * CVE-2026-1764 * CVE-2026-1765 * CVE-2026-1766 * CVE-2026-1767 CVSS scores: * CVE-2026-1764 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1764 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-1765 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves 4 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the localsearch-3.10.2-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * localsearch 3.10.2-2.1 * localsearch-lang 3.10.2-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1764.html * https://www.suse.com/security/cve/CVE-2026-1765.html * https://www.suse.com/security/cve/CVE-2026-1766.html * https://www.suse.com/security/cve/CVE-2026-1767.html . Update for localsearch resolves 4 moderate issues to enhance security in openSUSE Tumbleweed systems and applications.. openSUSE Tumbleweed, localsearch, security update, moderate issues, software vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.