Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21867-1

Опубликовано: 16 сент. 2026
Источник: suse-cvrf

Описание

Security update for mkvtoolnix

This update for mkvtoolnix fixes the following issues:

Changes in mkvtoolnix:

  • CVE-2026-90783: heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic (boo#1280126).

Список пакетов

openSUSE Leap 16.0
mkvtoolnix-95.0-bp160.2.1
mkvtoolnix-gui-95.0-bp160.2.1
mkvtoolnix-tools-95.0-bp160.2.1

Описание

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.


Затронутые продукты
openSUSE Leap 16.0:mkvtoolnix-95.0-bp160.2.1
openSUSE Leap 16.0:mkvtoolnix-gui-95.0-bp160.2.1
openSUSE Leap 16.0:mkvtoolnix-tools-95.0-bp160.2.1

Ссылки