CVE-2026-90783: MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound
MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.
Affected Software
Event History
Frequently Asked Questions
Which workflows are exposed to this issue?
The vulnerable code is reached when mkvmerge parses an AVI file. Systems that do not process untrusted AVI input with mkvmerge are not exposed through the described path.
What does an attacker need to exploit it?
An attacker needs to provide a specially crafted AVI file containing oversized ODML superindex entry counts and have it parsed by mkvmerge. The supplied vector indicates local access and user interaction are required.
How can I determine whether my installation is affected?
MKVToolNix versions through 101.0 are identified as affected. The provided data does not state the first fixed version.