FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mkvtoolnix -- Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound

Affected packages
mkvtoolnix < 102.0

Details

VuXML ID a738c927-b216-11f1-bc39-5404a68ad561
Discovery 2026-08-25
Entry 2026-09-16

Moritz Bunkus reports:

potential heap overflows/invalid memory access in the ODML index handling due to unsiged integer multiplication wrapping around (colloquially known as "overflowing") with specifically crafted AVI files. Affects only mkvmerge as the other tools do not read AVIs

References

CVE Name CVE-2026-90783
URL https://www.cve.org/CVERecord?id=CVE-2026-90783