CVE-2026-90783

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-13 13:16

Updated : 2026-09-14 19:18


NVD link : CVE-2026-90783

Mitre link : CVE-2026-90783

CVE.ORG link : CVE-2026-90783


JSON object : View

Products Affected

No product.

CWE
CWE-680

Integer Overflow to Buffer Overflow