Your message dated Mon, 14 Sep 2026 06:33:50 +0000
with message-id <[email protected]>
and subject line Bug#1147621: fixed in mkvtoolnix 101.0-2
has caused the Debian Bug report #1147621,
regarding mkvtoolnix: CVE-2026-90783
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1147621: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147621
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mkvtoolnix
Version: 101.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for mkvtoolnix.
CVE-2026-90783[0]:
| MKVToolNix through 101.0 contains a heap buffer overflow in the
| bundled avilib library's ODML superindex parser due to integer
| wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI
| file with oversized entry counts that cause an undersized heap
| allocation, allowing a heap buffer overflow when the file is parsed
| with mkvmerge.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-90783
https://www.cve.org/CVERecord?id=CVE-2026-90783
[1]
https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: mkvtoolnix
Source-Version: 101.0-2
Done: Christian Marillat <[email protected]>
We believe that the bug you reported is fixed in the latest version of
mkvtoolnix, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Christian Marillat <[email protected]> (supplier of updated mkvtoolnix
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 14 Sep 2026 08:14:20 +0200
Source: mkvtoolnix
Architecture: source
Version: 101.0-2
Distribution: unstable
Urgency: medium
Maintainer: Christian Marillat <[email protected]>
Changed-By: Christian Marillat <[email protected]>
Closes: 1147621
Changes:
mkvtoolnix (101.0-2) unstable; urgency=medium
.
* Add upstream patches to fix CVE-2026-90783 (Closes: #1147621)
Checksums-Sha1:
f9d91d30206b701d89bd38e97138a29d612488c2 2538 mkvtoolnix_101.0-2.dsc
78d8731eccab1aa3ec80529c0a299431dc759849 20496 mkvtoolnix_101.0-2.debian.tar.xz
677174013379c47c5500177a9fa7fe551cc1995a 18863
mkvtoolnix_101.0-2_source.buildinfo
Checksums-Sha256:
285de057f7653866c5c7b485a7094dc9b1f30265ac0c0a0bcc86e151de740d91 2538
mkvtoolnix_101.0-2.dsc
9eadcc6264705fcd560ab0c9bcfce27d3993813519014b90c7e173a75d7bd0be 20496
mkvtoolnix_101.0-2.debian.tar.xz
8803b854893570e06bdff27a311d30879ddf17f6ca75d59860f5083374a3ab15 18863
mkvtoolnix_101.0-2_source.buildinfo
Files:
6eefb5bc07c1295f784a8c2e3185a221 2538 graphics optional mkvtoolnix_101.0-2.dsc
5d07bfc09f525c33f4f4ede56a7c040c 20496 graphics optional
mkvtoolnix_101.0-2.debian.tar.xz
d4ea8b78f3073eace78f86d8f05bab23 18863 graphics optional
mkvtoolnix_101.0-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEpAH/mTaPofmBUt51XICMK2VVgRcFAmqnkPUACgkQXICMK2VV
gRdsgw//Rgm3il2S0TycfqcI1Urv8Iwd89BQVAd88u0smo2NqmsQurT/wynmhLKY
gq3lojZ7g1e1AFVg9aqYCB4CeHO3l+3YgPTx+q2eG3BWZ0INQ4iK8ZVUor7eEmGN
7CHVUXgB49CkvvEWy6zWnWxHN5/G6mr6ll0SLWofyc7mNZnpexb1XnyefVuOkOl5
maYp80I6rWOWdsrPS2dsb++EtQktTY2y+pq0AUTU+dx+bVt7F0a0ceKg21YHgPLP
IParTulpbbXsAAWEWZld5g7EXUiRvSWAo2OOuF5i7wPXFnStwYrVSDkWwBLB18c6
DhZf/qjxJfwAM5/C3NvVuwjxOGtjNxjKvQJaZA6gzawQFExtwpJtqOcwAVoMK+by
AU/Bpj41uPjgr57H9m5bmAQZbmZaIT7pciVsvp3T2J9XX7MFfi2t0f1HA0NLTNBN
+nHNu0/3iVLdeyhT8DHTuxj30j3t9cYgAeiNco7Yv9bOwCz36DYFGRtsl/YSxn4Q
Z7Qaj/cDx213HyrtLG6a0HEoQIPE7KNr5p3QrjjHCklfG+fGTxdSbNuPzYzNWGE5
Lk8+J+5r+phPNUXpzM2NebgrwNm2kxFyICPkb0nQlGKAMIvMgnDR7E0FanCSKY3i
T84xkhSLzOPckSQ2ZcpvS0YWgwiPmAg7UDCOb5LYDC07BGZOklI=
=g+MY
-----END PGP SIGNATURE-----
pgp_Cj5Z0kEdS.pgp
Description: PGP signature
--- End Message ---