[ubuntu/jammy-security] tracker-miners 3.3.3-0ubuntu0.20.04.4 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Thu Feb 5 15:59:10 UTC 2026
tracker-miners (3.3.3-0ubuntu0.20.04.4) jammy-security; urgency=medium
* SECURITY UPDATE: Heap Buffer Overflow
- debian/patches/CVE-2026-1764.patch: check for valid offsets
extracting MP3 performer tags in
src/tracker-extract/tracker-extract-mp3.c.
- CVE-2026-1764
* SECURITY UPDATE: NULL Pointer Dereference
- debian/patches/bug426.patch: bail out on 0-size frame for ID3v2.0
tags in src/tracker-extract/tracker-extract-mp3.c.
- No CVE number
* SECURITY UPDATE: Heap Buffer Overflow
- debian/patches/CVE-2026-1765.patch: check for buffer boundaries
extracting MP3 TXXX tags in
src/tracker-extract/tracker-extract-mp3.c.
- CVE-2026-1765
* SECURITY UPDATE: Heap Buffer Overflow
- debian/patches/CVE-2026-1766-pre1.patch: minor code refactor in
src/tracker-extract/tracker-extract-mp3.c.
- debian/patches/CVE-2026-1766.patch: refactor/fix handling of COMM
tags in src/tracker-extract/tracker-extract-mp3.c.
- CVE-2026-1766
* SECURITY UPDATE: Heap Buffer Overflow
- debian/patches/CVE-2026-1767.patch: fix accounting of offsets within
MP3 performer tags in src/tracker-extract/tracker-extract-mp3.c.
- CVE-2026-1767
tracker-miners (3.3.3-0ubuntu0.20.04.3) jammy; urgency=medium
* Allow epoll_create1 call in seccomp whitelist (LP: #1990630)
- d/p/seccomp-allow-epoll-create1.patch
tracker-miners (3.3.3-0ubuntu0.20.04.2) jammy; urgency=medium
[ Denison Barbosa ]
* Removes install section from tracker-extract.service to prevent it
from being enabled by systemd. It is a helper service that should be
managed by tracker-miner-fs.service, not systemd. (LP: #1779890)
- d/p/lp1779890-remove-install-section-from-tracker-extract-service.patch
- d/tracker-extract.postinst
Date: 2026-02-03 18:14:10.668425+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/tracker-miners/3.3.3-0ubuntu0.20.04.4
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list