{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/mkvtoolnix/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mkvtoolnix:mkvtoolnix:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-90783"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MKVToolNix (\u003c= 101.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MKVToolNix"],"content_html":"\u003cp\u003eMKVToolNix versions through 101.0 contain a critical heap buffer overflow vulnerability in the bundled avilib library. The flaw exists within the ODML superindex parser and is triggered by an integer wraparound during 32-bit arithmetic operations. An attacker can exploit this by distributing a specially crafted AVI file containing malicious entry counts. When a user parses this file using the mkvmerge utility, the application performs an undersized heap allocation. Subsequent operations then write data outside the bounds of this allocation, leading to a heap buffer overflow. This condition could allow an attacker to achieve arbitrary code execution or cause an application crash. Defenders should prioritize updating MKVToolNix to a version beyond 101.0 where the avilib library has been patched.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could lead to arbitrary code execution on systems where users interact with maliciously crafted AVI files via the mkvmerge command-line utility or the MKVToolNix GUI. This affects all platforms running the vulnerable versions of the software, including Windows, Linux, and macOS.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade MKVToolNix to the latest version, which contains the fix for the avilib library and CVE-2026-90783.\u003c/li\u003e\n\u003cli\u003eAudit file ingestion workflows that utilize mkvmerge for automated media processing to ensure they only process trusted files.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected crashes of the mkvmerge process, which may indicate attempted exploitation of heap-based vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T13:26:07Z","date_published":"2026-09-13T13:26:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mkvtoolnix-buffer-overflow/","summary":"MKVToolNix versions up to 101.0 are vulnerable to a heap buffer overflow in the avilib library, potentially allowing arbitrary code execution when processing crafted AVI files.","title":"Heap Buffer Overflow in MKVToolNix avilib Library","url":"https://feed.craftedsignal.io/briefs/2026-09-mkvtoolnix-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - MKVToolNix","version":"https://jsonfeed.org/version/1.1"}