Heap Buffer Overflow in MKVToolNix Affected by Integer Wraparound in avilib Library
CVE-2026-90783
8.5HIGH
What is CVE-2026-90783?
MKVToolNix versions up to 101.0 suffer from a heap buffer overflow vulnerability associated with the avilib library's ODML superindex parser. This issue arises from integer wraparound during 32-bit arithmetic, allowing attackers to craft malicious AVI files that contain oversized entry counts. These crafted files can lead to inadequate heap allocations, ultimately causing a buffer overflow when mkvmerge processes the file, posing serious security risks.
Affected Version(s)
MKVToolNix 0 <= 101.0
MKVToolNix 1495126138e086080f0163bee27fafbdf956a1d0
