CVE-2026-90783
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-680
- Published
- 2026-09-13
- Last modified
- 2026-09-14
Affected products
- Moritz Bunkus MKVToolNix
- Moritz Bunkus MKVToolNix
Weakness type
Related vulnerabilities
- CVE-2021-21783 — A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially cr
- CVE-2021-40417 — When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decodin
- CVE-2020-13576 — A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially cr
- CVE-2022-24834 — Heap overflow issue with the Lua cjson library used by Redis
- CVE-2025-53630 — Integer Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in gguf
- CVE-2020-6099 — An exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop V
- CVE-2021-32765 — Integer Overflow to Buffer Overflow in Hiredis
- CVE-2021-21862 — Multiple exploitable integer truncation vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Proje