SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90783

HIGH · CVSS 7.8

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

MKVToolNix versions up to 101.0 are vulnerable due to a heap buffer overflow in the avilib library's ODML superindex parser, stemming from integer wraparound in 32-bit arithmetic. This vulnerability allows attackers to create malicious AVI files that exploit undersized heap allocations, potentially leading to arbitrary code execution. Users and organizations utilizing MKVToolNix for media processing should prioritize patching to mitigate this high-severity risk.

CVE
CVE-2026-90783
Severity
HIGH
CVSS
7.8
EPSS
N/A

Original NVD Description

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.