MKVToolNix vulnerability

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.

Published 13 Sep 2026Updated 13 Sep 20264 sources
CVSS 8.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.