CVE-2026-90783

7.8

Moritz Bunkus · MKVToolNix

MKVToolNix contains a heap buffer overflow in the bundled avilib library, which can be triggered by parsing a malicious AVI file with mkvmerge.

Executive summary

A heap buffer overflow vulnerability in the MKVToolNix avilib library allows an attacker to achieve arbitrary code execution via a specially crafted AVI file.

Vulnerability

This vulnerability is a heap buffer overflow (CWE-680) located in the avilib library's ODML superindex parser. An unauthenticated attacker can trigger this flaw by providing a maliciously crafted AVI file to the mkvmerge utility, which performs an undersized heap allocation due to integer wraparound.

Business impact

The exploitation of this vulnerability can lead to memory corruption, potentially resulting in application crashes or the execution of arbitrary code within the context of the user running mkvmerge. Given the CVSS score of 7.8, this is a high-severity issue that poses a significant risk to workstations or servers that process untrusted media files, potentially leading to unauthorized system access or data compromise.

Remediation

Immediate Action: Update MKVToolNix to a version containing the fix identified in commit 1495126138e086080f0163bee27fafbdf956a1d0, or ensure you are utilizing a version released after the patch was integrated.

Proactive Monitoring: Monitor systems for unexpected mkvmerge process crashes or anomalous memory usage when processing media files.

Compensating Controls: Restrict the processing of AVI files from untrusted sources and utilize sandboxing technologies to isolate media conversion tasks from sensitive environments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize updating MKVToolNix installations to the latest patched version to eliminate the risk of heap-based memory corruption. Since the vulnerability is triggered during the parsing of media files, users should exercise caution when handling AVI files from unknown or unverified sources until updates are fully deployed across the environment.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Tristan Madani, per the CVE Program record.