Описание
Security update for mkvtoolnix
This update for mkvtoolnix fixes the following issues:
Changes in mkvtoolnix:
- CVE-2026-90783: heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic (boo#1280126).
Список пакетов
openSUSE Leap 16.0
mkvtoolnix-95.0-bp160.2.1
mkvtoolnix-gui-95.0-bp160.2.1
mkvtoolnix-tools-95.0-bp160.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1280126
- SUSE CVE CVE-2026-90783 page
Описание
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.
Затронутые продукты
openSUSE Leap 16.0:mkvtoolnix-95.0-bp160.2.1
openSUSE Leap 16.0:mkvtoolnix-gui-95.0-bp160.2.1
openSUSE Leap 16.0:mkvtoolnix-tools-95.0-bp160.2.1
Ссылки
- CVE-2026-90783
- SUSE Bug 1280126