Impact
MKVToolNix versions up to 101.0 embed the avilib library, which parses ODML superindex structures in AVI files. A 32‑bit integer wraparound in the array length calculation causes an undersized heap allocation when a malicious AVI file contains an oversized entry count. When mkvmerge processes such a file, the resulting heap buffer overflow can corrupt program memory, cause a crash, or potentially lead to arbitrary code execution on the host system.
Affected Systems
The vulnerability affects all releases of Moritz Bunkus’ MKVToolNix through version 101.0. Versions newer than 101.0 incorporate the upstream fix that removes the vulnerable parsing code and are not susceptible.
Risk and Exploitability
The CVSS score of 8.5 classifies this flaw as high severity, while the EPSS score indicates a very low but non‑zero probability of exploitation; it is not listed in the CISA KEV catalog. The likely attack vector is local file exploitation, requiring an attacker to supply a crafted AVI file that mkvmerge parses. If the adversary can influence the file input remotely, the threat could extend to a remote execution scenario.
OpenCVE Enrichment
Debian DLA
Debian DSA