๐Ÿ” CVE Alert

CVE-2026-90783

HIGH 7.8

MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

CWE CWE-680
Vendor moritz bunkus
Product mkvtoolnix
Published Sep 13, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for moritz bunkus mkvtoolnix

Be the first to know when new high vulnerabilities affecting moritz bunkus mkvtoolnix are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Moritz Bunkus / MKVToolNix
0 โ‰ค 101.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
codeberg.org: https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0 codeberg.org: https://codeberg.org/mbunkus/mkvtoolnix/src/tag/release-101.0/lib/avilib-0.6.10/avilib.c#L2552-L2570 codeberg.org: https://codeberg.org/mbunkus/mkvtoolnix vulncheck.com: https://www.vulncheck.com/advisories/mkvtoolnix-through-101.0-heap-buffer-overflow-via-avilib-odml-superindex-integer-wraparound

Credits

Tristan Madani