- Package:
- src:mkvtoolnix
- Source:
- src:mkvtoolnix
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-21 18:07:04 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for mkvtoolnix. CVE-2026-90783[0]: | MKVToolNix through 101.0 contains a heap buffer overflow in the | bundled avilib library's ODML superindex parser due to integer | wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI | file with oversized entry counts that cause an undersized heap | allocation, allowing a heap buffer overflow when the file is parsed | with mkvmerge. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-90783 https://www.cve.org/CVERecord?id=CVE-2026-90783 [1] https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hi, Could you update this CVE as the patch above isn't enough ? This patch is also needed : https://codeberg.org/mbunkus/mkvtoolnix/commit/13fd81db3ae2b79d41536a9663719df11780797e.patch Christian
We believe that the bug you reported is fixed in the latest version of mkvtoolnix, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1147621@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Christian Marillat <marillat@debian.org> (supplier of updated mkvtoolnix package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Mon, 14 Sep 2026 08:14:20 +0200 Source: mkvtoolnix Architecture: source Version: 101.0-2 Distribution: unstable Urgency: medium Maintainer: Christian Marillat <marillat@debian.org> Changed-By: Christian Marillat <marillat@debian.org> Closes: 1147621 Changes: mkvtoolnix (101.0-2) unstable; urgency=medium . * Add upstream patches to fix CVE-2026-90783 (Closes: #1147621) Checksums-Sha1: f9d91d30206b701d89bd38e97138a29d612488c2 2538 mkvtoolnix_101.0-2.dsc 78d8731eccab1aa3ec80529c0a299431dc759849 20496 mkvtoolnix_101.0-2.debian.tar.xz 677174013379c47c5500177a9fa7fe551cc1995a 18863 mkvtoolnix_101.0-2_source.buildinfo Checksums-Sha256: 285de057f7653866c5c7b485a7094dc9b1f30265ac0c0a0bcc86e151de740d91 2538 mkvtoolnix_101.0-2.dsc 9eadcc6264705fcd560ab0c9bcfce27d3993813519014b90c7e173a75d7bd0be 20496 mkvtoolnix_101.0-2.debian.tar.xz 8803b854893570e06bdff27a311d30879ddf17f6ca75d59860f5083374a3ab15 18863 mkvtoolnix_101.0-2_source.buildinfo Files: 6eefb5bc07c1295f784a8c2e3185a221 2538 graphics optional mkvtoolnix_101.0-2.dsc 5d07bfc09f525c33f4f4ede56a7c040c 20496 graphics optional mkvtoolnix_101.0-2.debian.tar.xz d4ea8b78f3073eace78f86d8f05bab23 18863 graphics optional mkvtoolnix_101.0-2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpAH/mTaPofmBUt51XICMK2VVgRcFAmqnkPUACgkQXICMK2VV gRdsgw//Rgm3il2S0TycfqcI1Urv8Iwd89BQVAd88u0smo2NqmsQurT/wynmhLKY gq3lojZ7g1e1AFVg9aqYCB4CeHO3l+3YgPTx+q2eG3BWZ0INQ4iK8ZVUor7eEmGN 7CHVUXgB49CkvvEWy6zWnWxHN5/G6mr6ll0SLWofyc7mNZnpexb1XnyefVuOkOl5 maYp80I6rWOWdsrPS2dsb++EtQktTY2y+pq0AUTU+dx+bVt7F0a0ceKg21YHgPLP IParTulpbbXsAAWEWZld5g7EXUiRvSWAo2OOuF5i7wPXFnStwYrVSDkWwBLB18c6 DhZf/qjxJfwAM5/C3NvVuwjxOGtjNxjKvQJaZA6gzawQFExtwpJtqOcwAVoMK+by AU/Bpj41uPjgr57H9m5bmAQZbmZaIT7pciVsvp3T2J9XX7MFfi2t0f1HA0NLTNBN +nHNu0/3iVLdeyhT8DHTuxj30j3t9cYgAeiNco7Yv9bOwCz36DYFGRtsl/YSxn4Q Z7Qaj/cDx213HyrtLG6a0HEoQIPE7KNr5p3QrjjHCklfG+fGTxdSbNuPzYzNWGE5 Lk8+J+5r+phPNUXpzM2NebgrwNm2kxFyICPkb0nQlGKAMIvMgnDR7E0FanCSKY3i T84xkhSLzOPckSQ2ZcpvS0YWgwiPmAg7UDCOb5LYDC07BGZOklI= =g+MY -----END PGP SIGNATURE-----
Hi Christian, Thank you for the update! Yes I just commited the above information to the security-tracker data (will show up udpated in at most 1h). https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/195ae95a20d6a0c24074cc0af458a03865d07b3b Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of mkvtoolnix, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1147621@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Moritz Mühlenhoff <jmm@debian.org> (supplier of updated mkvtoolnix package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Mon, 14 Sep 2026 20:31:08 +0200 Source: mkvtoolnix Architecture: source Version: 92.0-1+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Christian Marillat <marillat@debian.org> Changed-By: Moritz Mühlenhoff <jmm@debian.org> Closes: 1147621 Changes: mkvtoolnix (92.0-1+deb13u1) trixie-security; urgency=medium . * CVE-2026-90783 (Closes: #1147621) Checksums-Sha1: 772a258cb8c219ff2b9b3751a52327a32f7216aa 2549 mkvtoolnix_92.0-1+deb13u1.dsc 86bd634ec7b068d7fcfd3a6547a2f8de53ce9acc 11317576 mkvtoolnix_92.0.orig.tar.xz cfae1267b7178d17b855fd211265878c55b6ec70 833 mkvtoolnix_92.0.orig.tar.xz.asc 55a5ee7f485513e3ba1e3d0174d00e8ffa27af10 19696 mkvtoolnix_92.0-1+deb13u1.debian.tar.xz 74c616939e89d85e28984cec07b338e19e721e62 19763 mkvtoolnix_92.0-1+deb13u1_amd64.buildinfo Checksums-Sha256: 910fd3c2dfc2906809c06ed5322e706aeea2c4c58840e15c21081327131f9f7a 2549 mkvtoolnix_92.0-1+deb13u1.dsc 657c1aa1c176510e57de12716492ca9d0b59ba5f17ace2f76ffe77c592c88929 11317576 mkvtoolnix_92.0.orig.tar.xz 9756b43ef805e1a6f3793660fd644e082a577a433c2785ea470552aa9cd981c5 833 mkvtoolnix_92.0.orig.tar.xz.asc 57e2e0fac92a9b43c096a92ba8f883022e710cdac41c8c7c7f944f33872b63ac 19696 mkvtoolnix_92.0-1+deb13u1.debian.tar.xz 39e5ebc6cc88ed0482baf9b96292ab62875d6571201b671148d3b5accf0f9a41 19763 mkvtoolnix_92.0-1+deb13u1_amd64.buildinfo Files: a330821578d0ad730835e0f609fc426b 2549 graphics optional mkvtoolnix_92.0-1+deb13u1.dsc 1db28ee4618d257c0be8e01aa2dbcb69 11317576 graphics optional mkvtoolnix_92.0.orig.tar.xz 91144461f58088c59511099b56bf7a9c 833 graphics optional mkvtoolnix_92.0.orig.tar.xz.asc 0016afa7605216f837507f661bfc077a 19696 graphics optional mkvtoolnix_92.0-1+deb13u1.debian.tar.xz 2f160cdfe51abbb70609f8bfad85e2c5 19763 graphics optional mkvtoolnix_92.0-1+deb13u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqpZlkACgkQEMKTtsN8 TjY51Q/6AijwuP7tsrr3WZu1NaI+XsypjXJik8/G9IvhCtkD9KzAdKd7b2ADrSnF rqRuO9f0n7JBgP7AEi4iMiEAXalttHjOrQNi+iAgq6yZ0xgfzDvNVIprLDuA67+m pVCaecK5pclhqw4toLAdW0kr5+0VqDnRe4x9MgNMQX+u0CeaAjZRC+wUQ2tpvfi0 R3BDV/ZLBvdhxlHSzi9brn3o+AbAAfEyMSkXkEVJOwE73CEV2YG2ucW/b2w/VHX8 F7K+jDvqjHNklX/y9E9TXBJqJgvEqmtyrDfZK6wM7LjiLZ0kGqI0Zb9j+5D1HGCf ZOwcEPplenfWmQNB/a5Ecs76sW7rJaboTrSNUKdxiuMGp0hOXpu7QdxU+09TxV+t KxqDvxjjye71rJvOW+Nf+w3MmZNoSOhET41DCD1LjDp3dSPKgHHhkVqzc8fLSdXf 4CEVNIFRUmJk4xpw6eYbJVhk3Z2q6GkIm/tjYViZegKxVTGgZOWjMyjirvEGXuau ZDjVX1buw2FkliOxxccfLyGMXJ6FJzbiatCPndpM8NhaZmEmXowKQskhiP6/qG5a nFZ2ceszM22zJK94ncQnKRHpvFVpUl++jSwIN/rMX4SzrG3JRZvRhbCh8wvQvZ8b 6N5jz7QG/7WKYo6JWJHMzlpgDoZAERF7QdwE0IyIXlGc+WrEdGY= =c6dV -----END PGP SIGNATURE-----