{"id":"SUSE-SU-2026:21854-1","summary":"Security update for localsearch","details":"This update for localsearch fixes the following issues:\n\n- CVE-2026-1764: Fixed a heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files. (bsc#1257606)\n- CVE-2026-1765: Fixed a Denial of Service and potential information disclosure via crafted MP3 files. (bsc#1257607)\n- CVE-2026-1766: Fixed a Denial of Service and information disclosure via malformed MP3 files. (bsc#1257608)\n- CVE-2026-1767: Fixed a heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags. (bsc#1257609)\n","modified":"2026-06-02T18:24:30.576248116Z","published":"2026-05-27T16:46:46Z","related":["CVE-2026-1764","CVE-2026-1765","CVE-2026-1766","CVE-2026-1767"],"upstream":["CVE-2026-1764","CVE-2026-1765","CVE-2026-1766","CVE-2026-1767"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621854-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257606"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257607"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257608"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257609"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1764"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1765"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1766"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1767"}],"schema_version":"1.7.5"}