MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge. | |
| Title | MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound | |
| Weaknesses | CWE-680 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T12:22:02.443Z
Reserved: 2026-09-13T12:01:36.028Z
Link: CVE-2026-90783
No data.
Status : Received
Published: 2026-09-13T13:16:29.560
Modified: 2026-09-13T13:16:29.560
Link: CVE-2026-90783
No data.
OpenCVE Enrichment
No data.
Weaknesses