CVE-2026-90783 PUBLISHED

MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound

Assigner: VulnCheck
Reserved: 13.09.2026 Published: 13.09.2026 Updated: 13.09.2026

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Moritz Bunkus
Product MKVToolNix
Versions Default: unaffected
  • affected from 0 to 101.0 (incl.)
  • Version 1495126138e086080f0163bee27fafbdf956a1d0 is unaffected

Credits

  • Tristan Madani finder

References

Problem Types

  • Integer Overflow to Buffer Overflow CWE