#1147621 mkvtoolnix: CVE-2026-90783

Package:
src:mkvtoolnix
Source:
src:mkvtoolnix
Submitter:
Salvatore Bonaccorso
Date:
2026-09-21 18:07:04 UTC
Severity:
normal
Tags:
#1147621#5
Date:
2026-09-13 21:03:19 UTC
From:
To:
Hi,

The following vulnerability was published for mkvtoolnix.

CVE-2026-90783[0]:
| MKVToolNix through 101.0 contains a heap buffer overflow in the
| bundled avilib library's ODML superindex parser due to integer
| wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI
| file with oversized entry counts that cause an undersized heap
| allocation, allowing a heap buffer overflow when the file is parsed
| with mkvmerge.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90783
https://www.cve.org/CVERecord?id=CVE-2026-90783
[1] https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147621#10
Date:
2026-09-14 06:06:56 UTC
From:
To:
Hi,

Could you update this CVE as the patch above isn't enough ?

This patch is also needed :

https://codeberg.org/mbunkus/mkvtoolnix/commit/13fd81db3ae2b79d41536a9663719df11780797e.patch

Christian

#1147621#15
Date:
2026-09-14 06:33:50 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
mkvtoolnix, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147621@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christian Marillat <marillat@debian.org> (supplier of updated mkvtoolnix package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 14 Sep 2026 08:14:20 +0200
Source: mkvtoolnix
Architecture: source
Version: 101.0-2
Distribution: unstable
Urgency: medium
Maintainer: Christian Marillat <marillat@debian.org>
Changed-By: Christian Marillat <marillat@debian.org>
Closes: 1147621
Changes:
 mkvtoolnix (101.0-2) unstable; urgency=medium
 .
   * Add upstream patches to fix CVE-2026-90783 (Closes: #1147621)
Checksums-Sha1:
 f9d91d30206b701d89bd38e97138a29d612488c2 2538 mkvtoolnix_101.0-2.dsc
 78d8731eccab1aa3ec80529c0a299431dc759849 20496 mkvtoolnix_101.0-2.debian.tar.xz
 677174013379c47c5500177a9fa7fe551cc1995a 18863 mkvtoolnix_101.0-2_source.buildinfo
Checksums-Sha256:
 285de057f7653866c5c7b485a7094dc9b1f30265ac0c0a0bcc86e151de740d91 2538 mkvtoolnix_101.0-2.dsc
 9eadcc6264705fcd560ab0c9bcfce27d3993813519014b90c7e173a75d7bd0be 20496 mkvtoolnix_101.0-2.debian.tar.xz
 8803b854893570e06bdff27a311d30879ddf17f6ca75d59860f5083374a3ab15 18863 mkvtoolnix_101.0-2_source.buildinfo
Files:
 6eefb5bc07c1295f784a8c2e3185a221 2538 graphics optional mkvtoolnix_101.0-2.dsc
 5d07bfc09f525c33f4f4ede56a7c040c 20496 graphics optional mkvtoolnix_101.0-2.debian.tar.xz
 d4ea8b78f3073eace78f86d8f05bab23 18863 graphics optional mkvtoolnix_101.0-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpAH/mTaPofmBUt51XICMK2VVgRcFAmqnkPUACgkQXICMK2VV
gRdsgw//Rgm3il2S0TycfqcI1Urv8Iwd89BQVAd88u0smo2NqmsQurT/wynmhLKY
gq3lojZ7g1e1AFVg9aqYCB4CeHO3l+3YgPTx+q2eG3BWZ0INQ4iK8ZVUor7eEmGN
7CHVUXgB49CkvvEWy6zWnWxHN5/G6mr6ll0SLWofyc7mNZnpexb1XnyefVuOkOl5
maYp80I6rWOWdsrPS2dsb++EtQktTY2y+pq0AUTU+dx+bVt7F0a0ceKg21YHgPLP
IParTulpbbXsAAWEWZld5g7EXUiRvSWAo2OOuF5i7wPXFnStwYrVSDkWwBLB18c6
DhZf/qjxJfwAM5/C3NvVuwjxOGtjNxjKvQJaZA6gzawQFExtwpJtqOcwAVoMK+by
AU/Bpj41uPjgr57H9m5bmAQZbmZaIT7pciVsvp3T2J9XX7MFfi2t0f1HA0NLTNBN
+nHNu0/3iVLdeyhT8DHTuxj30j3t9cYgAeiNco7Yv9bOwCz36DYFGRtsl/YSxn4Q
Z7Qaj/cDx213HyrtLG6a0HEoQIPE7KNr5p3QrjjHCklfG+fGTxdSbNuPzYzNWGE5
Lk8+J+5r+phPNUXpzM2NebgrwNm2kxFyICPkb0nQlGKAMIvMgnDR7E0FanCSKY3i
T84xkhSLzOPckSQ2ZcpvS0YWgwiPmAg7UDCOb5LYDC07BGZOklI=
=g+MY
-----END PGP SIGNATURE-----

#1147621#20
Date:
2026-09-14 06:53:24 UTC
From:
To:
Hi Christian,

Thank you for the update! Yes I just commited the above information to
the security-tracker data (will show up udpated in at most 1h).

https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/195ae95a20d6a0c24074cc0af458a03865d07b3b

Regards,
Salvatore

#1147621#25
Date:
2026-09-21 18:04:54 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
mkvtoolnix, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147621@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Moritz Mühlenhoff <jmm@debian.org> (supplier of updated mkvtoolnix package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 14 Sep 2026 20:31:08 +0200
Source: mkvtoolnix
Architecture: source
Version: 92.0-1+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Christian Marillat <marillat@debian.org>
Changed-By: Moritz Mühlenhoff <jmm@debian.org>
Closes: 1147621
Changes:
 mkvtoolnix (92.0-1+deb13u1) trixie-security; urgency=medium
 .
   * CVE-2026-90783 (Closes: #1147621)
Checksums-Sha1:
 772a258cb8c219ff2b9b3751a52327a32f7216aa 2549 mkvtoolnix_92.0-1+deb13u1.dsc
 86bd634ec7b068d7fcfd3a6547a2f8de53ce9acc 11317576 mkvtoolnix_92.0.orig.tar.xz
 cfae1267b7178d17b855fd211265878c55b6ec70 833 mkvtoolnix_92.0.orig.tar.xz.asc
 55a5ee7f485513e3ba1e3d0174d00e8ffa27af10 19696 mkvtoolnix_92.0-1+deb13u1.debian.tar.xz
 74c616939e89d85e28984cec07b338e19e721e62 19763 mkvtoolnix_92.0-1+deb13u1_amd64.buildinfo
Checksums-Sha256:
 910fd3c2dfc2906809c06ed5322e706aeea2c4c58840e15c21081327131f9f7a 2549 mkvtoolnix_92.0-1+deb13u1.dsc
 657c1aa1c176510e57de12716492ca9d0b59ba5f17ace2f76ffe77c592c88929 11317576 mkvtoolnix_92.0.orig.tar.xz
 9756b43ef805e1a6f3793660fd644e082a577a433c2785ea470552aa9cd981c5 833 mkvtoolnix_92.0.orig.tar.xz.asc
 57e2e0fac92a9b43c096a92ba8f883022e710cdac41c8c7c7f944f33872b63ac 19696 mkvtoolnix_92.0-1+deb13u1.debian.tar.xz
 39e5ebc6cc88ed0482baf9b96292ab62875d6571201b671148d3b5accf0f9a41 19763 mkvtoolnix_92.0-1+deb13u1_amd64.buildinfo
Files:
 a330821578d0ad730835e0f609fc426b 2549 graphics optional mkvtoolnix_92.0-1+deb13u1.dsc
 1db28ee4618d257c0be8e01aa2dbcb69 11317576 graphics optional mkvtoolnix_92.0.orig.tar.xz
 91144461f58088c59511099b56bf7a9c 833 graphics optional mkvtoolnix_92.0.orig.tar.xz.asc
 0016afa7605216f837507f661bfc077a 19696 graphics optional mkvtoolnix_92.0-1+deb13u1.debian.tar.xz
 2f160cdfe51abbb70609f8bfad85e2c5 19763 graphics optional mkvtoolnix_92.0-1+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqpZlkACgkQEMKTtsN8
TjY51Q/6AijwuP7tsrr3WZu1NaI+XsypjXJik8/G9IvhCtkD9KzAdKd7b2ADrSnF
rqRuO9f0n7JBgP7AEi4iMiEAXalttHjOrQNi+iAgq6yZ0xgfzDvNVIprLDuA67+m
pVCaecK5pclhqw4toLAdW0kr5+0VqDnRe4x9MgNMQX+u0CeaAjZRC+wUQ2tpvfi0
R3BDV/ZLBvdhxlHSzi9brn3o+AbAAfEyMSkXkEVJOwE73CEV2YG2ucW/b2w/VHX8
F7K+jDvqjHNklX/y9E9TXBJqJgvEqmtyrDfZK6wM7LjiLZ0kGqI0Zb9j+5D1HGCf
ZOwcEPplenfWmQNB/a5Ecs76sW7rJaboTrSNUKdxiuMGp0hOXpu7QdxU+09TxV+t
KxqDvxjjye71rJvOW+Nf+w3MmZNoSOhET41DCD1LjDp3dSPKgHHhkVqzc8fLSdXf
4CEVNIFRUmJk4xpw6eYbJVhk3Z2q6GkIm/tjYViZegKxVTGgZOWjMyjirvEGXuau
ZDjVX1buw2FkliOxxccfLyGMXJ6FJzbiatCPndpM8NhaZmEmXowKQskhiP6/qG5a
nFZ2ceszM22zJK94ncQnKRHpvFVpUl++jSwIN/rMX4SzrG3JRZvRhbCh8wvQvZ8b
6N5jz7QG/7WKYo6JWJHMzlpgDoZAERF7QdwE0IyIXlGc+WrEdGY=
=c6dV
-----END PGP SIGNATURE-----