# CVE-2026-90783

## Summary

- **CVE ID:** CVE-2026-90783
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-680
- **Published:** Sep 13, 2026
- **Last Modified:** Sep 14, 2026

## Description

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

## Affected Products

- Moritz Bunkus — MKVToolNix (0)
- Moritz Bunkus — MKVToolNix (1495126138e086080f0163bee27fafbdf956a1d0)

## References

- [CNA](https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0)
- [CNA](https://codeberg.org/mbunkus/mkvtoolnix/src/tag/release-101.0/lib/avilib-0.6.10/avilib.c#L2552-L2570)
- [CNA](https://codeberg.org/mbunkus/mkvtoolnix)
- [CNA](https://www.vulncheck.com/advisories/mkvtoolnix-through-101.0-heap-buffer-overflow-via-avilib-odml-superindex-integer-wraparound)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._