UBUNTU-CVE-2026-5673

Source
https://ubuntu.com/security/CVE-2026-5673
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-5673
Upstream
  • CVE-2026-5673
Published
2026-04-06T10:16:00Z
Modified
2026-05-20T16:26:24.923848536Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H CVSS Calculator
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the aviparseinput_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.

References

Affected packages

Ubuntu:16.04:LTS
asc

Package

Name
asc
Purl
pkg:deb/ubuntu/asc?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.0.0-1build1
2.6.1.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.1.0-1",
            "binary_name": "asc"
        },
        {
            "binary_version": "2.6.1.0-1",
            "binary_name": "asc-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
mkvtoolnix

Package

Name
mkvtoolnix
Purl
pkg:deb/ubuntu/mkvtoolnix?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.2.0-2
8.5.1-1
8.5.2-1
8.6.0-1
8.6.1-1
8.7.0-1
8.8.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "8.8.0-1",
            "binary_name": "mkvtoolnix"
        },
        {
            "binary_version": "8.8.0-1",
            "binary_name": "mkvtoolnix-gui"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
ogmrip

Package

Name
ogmrip
Purl
pkg:deb/ubuntu/ogmrip?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0-0ubuntu1
1.0.1-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.0.1-1",
            "binary_name": "libogmrip1"
        },
        {
            "binary_version": "1.0.1-1",
            "binary_name": "ogmrip"
        },
        {
            "binary_version": "1.0.1-1",
            "binary_name": "ogmrip-plugins"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
Ubuntu:18.04:LTS
asc

Package

Name
asc
Purl
pkg:deb/ubuntu/asc?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.1.0-2
2.6.1.0-2build1
2.6.1.0-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.1.0-3",
            "binary_name": "asc"
        },
        {
            "binary_version": "2.6.1.0-3",
            "binary_name": "asc-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
mkvtoolnix

Package

Name
mkvtoolnix
Purl
pkg:deb/ubuntu/mkvtoolnix?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

15.*
15.0.0-1
15.0.0-1build1
17.*
17.0.0-2
18.*
18.0.0-1
19.*
19.0.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "19.0.0-1",
            "binary_name": "mkvtoolnix"
        },
        {
            "binary_version": "19.0.0-1",
            "binary_name": "mkvtoolnix-gui"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
ogmrip

Package

Name
ogmrip
Purl
pkg:deb/ubuntu/ogmrip?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.1-1build2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.0.1-1build2",
            "binary_name": "libogmrip1"
        },
        {
            "binary_version": "1.0.1-1build2",
            "binary_name": "ogmrip"
        },
        {
            "binary_version": "1.0.1-1build2",
            "binary_name": "ogmrip-plugins"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
Ubuntu:20.04:LTS
asc

Package

Name
asc
Purl
pkg:deb/ubuntu/asc?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.1.0-5build1
2.6.1.0-6
2.6.1.0-6build1
2.6.1.0-6build2
2.6.1.0-6build3
2.6.1.0-6build4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.1.0-6build4",
            "binary_name": "asc"
        },
        {
            "binary_version": "2.6.1.0-6build4",
            "binary_name": "asc-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
mkvtoolnix

Package

Name
mkvtoolnix
Purl
pkg:deb/ubuntu/mkvtoolnix?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

37.*
37.0.0-1build1
38.*
38.0.0-1
39.*
39.0.0-1
40.*
40.0.0-1
40.0.0-3
41.*
41.0.0-1
42.*
42.0.0-1
43.*
43.0.0-1
43.0.0-1ubuntu1
43.0.0-1ubuntu2
44.*
44.0.0-1ubuntu1
45.*
45.0.0-1ubuntu1
45.0.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "45.0.0-2",
            "binary_name": "mkvtoolnix"
        },
        {
            "binary_version": "45.0.0-2",
            "binary_name": "mkvtoolnix-gui"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
ogmrip

Package

Name
ogmrip
Purl
pkg:deb/ubuntu/ogmrip?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.1-1build2
1.0.1-2
1.0.1-2build1
1.0.1-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.0.1-3",
            "binary_name": "libogmrip1"
        },
        {
            "binary_version": "1.0.1-3",
            "binary_name": "ogmrip"
        },
        {
            "binary_version": "1.0.1-3",
            "binary_name": "ogmrip-plugins"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
Ubuntu:22.04:LTS
asc

Package

Name
asc
Purl
pkg:deb/ubuntu/asc?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.1.0-7build3
2.6.1.0-8
2.6.1.0-8build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.1.0-8build1",
            "binary_name": "asc"
        },
        {
            "binary_version": "2.6.1.0-8build1",
            "binary_name": "asc-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
mkvtoolnix

Package

Name
mkvtoolnix
Purl
pkg:deb/ubuntu/mkvtoolnix?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

60.*
60.0.0-2
62.*
62.0.0-1build1
63.*
63.0.0-1
64.*
64.0.0-1
65.*
65.0.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "65.0.0-1",
            "binary_name": "mkvtoolnix"
        },
        {
            "binary_version": "65.0.0-1",
            "binary_name": "mkvtoolnix-gui"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
ogmrip

Package

Name
ogmrip
Purl
pkg:deb/ubuntu/ogmrip?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.1-3.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.0.1-3.1",
            "binary_name": "libogmrip1"
        },
        {
            "binary_version": "1.0.1-3.1",
            "binary_name": "ogmrip"
        },
        {
            "binary_version": "1.0.1-3.1",
            "binary_name": "ogmrip-plugins"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
Ubuntu:24.04:LTS
asc

Package

Name
asc
Purl
pkg:deb/ubuntu/asc?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.1.0-9build2
2.6.1.0-9build3
2.6.1.0-9build4
2.6.1.0-9build5

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.1.0-9build5",
            "binary_name": "asc"
        },
        {
            "binary_version": "2.6.1.0-9build5",
            "binary_name": "asc-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
mkvtoolnix

Package

Name
mkvtoolnix
Purl
pkg:deb/ubuntu/mkvtoolnix?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

78.*
78.0-2
79.*
79.0-1
80.*
80.0-1
81.*
81.0-1
81.0-1build1
82.*
82.0-1
82.0-1build1
82.0-1build2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "82.0-1build2",
            "binary_name": "mkvtoolnix"
        },
        {
            "binary_version": "82.0-1build2",
            "binary_name": "mkvtoolnix-gui"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
Ubuntu:25.10
asc

Package

Name
asc
Purl
pkg:deb/ubuntu/asc?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.1.0-9build5

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.1.0-9build5",
            "binary_name": "asc"
        },
        {
            "binary_version": "2.6.1.0-9build5",
            "binary_name": "asc-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
mkvtoolnix

Package

Name
mkvtoolnix
Purl
pkg:deb/ubuntu/mkvtoolnix?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

90.*
90.0-1build1
92.*
92.0-1
92.0-1build2
94.*
94.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "94.0-1",
            "binary_name": "mkvtoolnix"
        },
        {
            "binary_version": "94.0-1",
            "binary_name": "mkvtoolnix-gui"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
ogmrip

Package

Name
ogmrip
Purl
pkg:deb/ubuntu/ogmrip?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.1-5
1.0.1-5build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.0.1-5build1",
            "binary_name": "libogmrip1"
        },
        {
            "binary_version": "1.0.1-5build1",
            "binary_name": "ogmrip"
        },
        {
            "binary_version": "1.0.1-5build1",
            "binary_name": "ogmrip-plugins"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
Ubuntu:26.04:LTS
asc

Package

Name
asc
Purl
pkg:deb/ubuntu/asc?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.1.0-9build5
2.6.1.0-9build6

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.1.0-9build6",
            "binary_name": "asc"
        },
        {
            "binary_version": "2.6.1.0-9build6",
            "binary_name": "asc-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
mkvtoolnix

Package

Name
mkvtoolnix
Purl
pkg:deb/ubuntu/mkvtoolnix?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

94.*
94.0-1
95.*
95.0-1
96.*
96.0-1
97.*
97.0-1
97.0-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "97.0-1build1",
            "binary_name": "mkvtoolnix"
        },
        {
            "binary_version": "97.0-1build1",
            "binary_name": "mkvtoolnix-gui"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"
ogmrip

Package

Name
ogmrip
Purl
pkg:deb/ubuntu/ogmrip?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.1-5build1
1.0.1-5build2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.0.1-5build2",
            "binary_name": "libogmrip1"
        },
        {
            "binary_version": "1.0.1-5build2",
            "binary_name": "ogmrip"
        },
        {
            "binary_version": "1.0.1-5build2",
            "binary_name": "ogmrip-plugins"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-5673.json"