CVE-2019-2126
published 2019-08-20CVE-2019-2126: In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code…
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
5.39%
91.8th percentile
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| godotengine | godot | >= 0 < 3.2-stable-2ubuntu0.1~esm1 | 3.2-stable-2ubuntu0.1~esm1 |
| godotengine | godot | >= 0 < 3.2.3-stable-1ubuntu0.1~esm1 | 3.2.3-stable-1ubuntu0.1~esm1 |
| godotengine | godot | >= 0 < 3.5.2-stable-2ubuntu0.24.04.1~esm1 | 3.5.2-stable-2ubuntu0.24.04.1~esm1 |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| opensuse | leap | — | — |
| webmproject | libvpx | >= 0 < 1.7.0-3ubuntu0.18.04.1 | 1.7.0-3ubuntu0.18.04.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Godot Engine vulnerabilities
vendor_ubuntu·2025-06-18·CVSS 8.8
CVE-2021-26826 [HIGH] Godot Engine vulnerabilities
Title: Godot Engine vulnerabilities
Summary: Several security issues were fixed in Godot Engine.
It was discovered that the Godot Engine did not properly handle
certain malformed WebM media files. If the Godot Engine opened a
specially crafted WebM file, a remote attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2019-2126)
It was discovered that the Godot Engine did not properly handle
certain malformed TGA image files. If the Godot Engine opened a
specially crafted TGA image file, a remote attacker could cause
a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2021-26825, CVE-2021-26826)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libvpx vulnerabilities
vendor_ubuntu·2019-11-25
CVE-2017-13194 libvpx vulnerabilities
Title: libvpx vulnerabilities
Summary: Several security issues were fixed in libvpx.
It was discovered that libvpx did not properly handle certain malformed
WebM media files. If an application using libvpx opened a specially crafted
WebM file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvpx: Double free in ParseContentEncodingEntry() in mkvparser.cc
vendor_redhat·2019-10-26·CVSS 8.8
CVE-2019-2126 [HIGH] CWE-672 libvpx: Double free in ParseContentEncodingEntry() in mkvparser.cc
libvpx: Double free in ParseContentEncodingEntry() in mkvparser.cc
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.
Package: libvpx (Red Hat Enterprise Linux 6) - Out of support scope
Package: libvpx (Red Hat Enterprise Linux 7) - Not affected
Android
CVE-2019-2126: Android Security Bulletin 2019-08-01
CVE: CVE-2019-2126
Severity: HIGH
Type: RCE
Affected AOSP versions: 7
vendor_android·2019-08-01·CVSS 8.8
CVE-2019-2126 [HIGH] CVE-2019-2126: Android Security Bulletin 2019-08-01
CVE: CVE-2019-2126
Severity: HIGH
Type: RCE
Affected AOSP versions: 7
Android Security Bulletin 2019-08-01
CVE: CVE-2019-2126
Severity: HIGH
Type: RCE
Affected AOSP versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1, 9
References: A-127702368
[2]
OSV
godot vulnerabilities
osv·2025-06-18·CVSS 8.8
CVE-2019-2126 [HIGH] godot vulnerabilities
godot vulnerabilities
It was discovered that the Godot Engine did not properly handle
certain malformed WebM media files. If the Godot Engine opened a
specially crafted WebM file, a remote attacker could cause a denial
of service, or possibly execute arbitrary code. (CVE-2019-2126)
It was discovered that the Godot Engine did not properly handle
certain malformed TGA image files. If the Godot Engine opened a
specially crafted TGA image file, a remote attacker could cause
a denial of service, or possibly execute arbitrary code. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2021-26825, CVE-2021-26826)
GHSA
GHSA-jxxw-46w4-3vhv: In ParseContentEncodingEntry of mkvparser
ghsa_unreviewed·2022-05-24
CVE-2019-2126 [HIGH] CWE-415 GHSA-jxxw-46w4-3vhv: In ParseContentEncodingEntry of mkvparser
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.
OSV
CVE-2019-2126: In ParseContentEncodingEntry of mkvparser
osv·2019-08-20·CVSS 8.8
CVE-2019-2126 [HIGH] CVE-2019-2126: In ParseContentEncodingEntry of mkvparser
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00049.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQSTK442ATWJOR4TU3MR6C3N5A6NDFFN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2IIA3RSYABBUCFIHXIRVUT5CTJVWWZ6/https://source.android.com/security/bulletin/2019-08-01https://usn.ubuntu.com/4199-1/http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00049.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQSTK442ATWJOR4TU3MR6C3N5A6NDFFN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U2IIA3RSYABBUCFIHXIRVUT5CTJVWWZ6/https://source.android.com/security/bulletin/2019-08-01https://usn.ubuntu.com/4199-1/
2019-08-20
Published