Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6502-1 | mkvtoolnix security update |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moritz Bunkus
Moritz Bunkus mkvtoolnix |
|
| Vendors & Products |
Moritz Bunkus
Moritz Bunkus mkvtoolnix |
Sun, 13 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge. | |
| Title | MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound | |
| Weaknesses | CWE-680 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T18:14:43.959Z
Reserved: 2026-09-13T12:01:36.028Z
Link: CVE-2026-90783
Updated: 2026-09-14T17:32:47.881Z
Status : Received
Published: 2026-09-13T13:16:29.560
Modified: 2026-09-14T19:18:10.193
Link: CVE-2026-90783
No data.
OpenCVE Enrichment
Updated: 2026-09-15T18:00:17Z
Debian DSA