ZeroHour

CVE-2026-90783

large

Heap Buffer Overflow in MKVToolNix (mkvmerge) ODML AVI Parser

CVSS 4.0
8.5 high
EPSS
Published
()
Modified
AI analysis

MKVToolNix through version 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser, caused by integer wraparound in 32-bit arithmetic when computing an entry count. An attacker crafts a malicious AVI file with oversized index entry counts, which drives an undersized heap allocation that is subsequently overflowed when mkvmerge parses the file. Successful exploitation requires a victim to open or process the attacker-supplied AVI file, consistent with the local attack vector and user-interaction requirement in the CVSS 4.0 score (8.5, high), and can yield high impacts to confidentiality, integrity, and availability, such as application crashes or potential code execution under the user's privileges. Anyone running mkvmerge or the MKVToolNix GUI on versions through 101.0 to process untrusted AVI files is affected. No public proof of concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog.

What to do: Upgrade MKVToolNix to a release newer than 101.0 as soon as a fixed version is available from your distribution or upstream. Until patched, avoid using mkvmerge or the MKVToolNix GUI to open AVI files from untrusted or unknown sources, and scan suspicious media files in an isolated environment first. Defenders should watch for crashes or anomalous behavior in automated media-processing pipelines that ingest user-supplied AVI files.

Affected
Moritz Bunkus MKVToolNixthrough 101.0
Estimated exposure
large≈ hundreds of thousands to low millions of desktop installs (estimated) — MKVToolNix is a widely used open-source cross-platform video tool packaged in major Linux distributions (Debian, Ubuntu, Fedora, Arch) and downloaded millions of times via FossHub and GitHub releases, but no active-install telemetry…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

Weakness
CWE-680
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.