Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing
Published Apr 6, 2026
7.1
HIGHCVSS 3.1
EPSS 0.16%
Description
A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 6 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
- n/a
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
libtheora
Fix deferred
Red Hat Enterprise Linux 6
libtheora
Fix deferred
Red Hat Enterprise Linux 7
libtheora
Fix deferred
Red Hat Enterprise Linux 8
libtheora
Fix deferred
Red Hat Enterprise Linux 9
libtheora
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libtheora | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | libtheora | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | libtheora | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | libtheora | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | libtheora | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, users should avoid opening untrusted AVI files. Exercise caution when handling AVI files from unknown or suspicious sources.
Red Hat statement
Moderate: A heap-based out-of-bounds read flaw in libtheora's AVI parser can lead to a denial-of-service or information leak. Exploitation requires a local attacker to trick a user into opening a specially crafted AVI file.
Red Hat mitigation
To mitigate this issue, users should avoid opening untrusted AVI files. Exercise caution when handling AVI files from unknown or suspicious sources.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-5673 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2455340 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/xiph/theora/issues/24 ExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-5673
- https://www.cve.org/CVERecord?id=CVE-2026-5673
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-5673 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2455340 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://github.com/xiph/theora/issues/24 | ExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-5673 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-5673 |
Change history (0)
No recorded changes yet.