This is one of the things that really scares me, not just in Linux but in every operating system. Afaik, metadata scanning is one of the biggest zero-click attack vectors on iOS.
In Linux I try to execute as much as possible under a sandbox (firejail), hoping that this makes any difference, but deep inside I am terrified about the piles upon piles of ancient C code running from Gnome all the way down to the driver stack...
Edit - from the article:
"There are two parts to the problem. The first is that the scanner (cue_scanner.l, line 132) uses atoi to scan the integers: [...] atoi does not check for integer overflow, so it is easy to construct a negative index. [...]
The second part of the problem (and this is the actual vulnerability) is that track_set_index does not check that i ≥ 0"
I hate to be that guy, but maybe C should no longer be considered a valid option for parsing unknown input, aka the first line of defense...