Back

HIGH

Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing

Published Apr 6, 2026

Description

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.

Affected products

Remediation

Vendor solution

To mitigate this issue, users should avoid opening untrusted AVI files. Exercise caution when handling AVI files from unknown or suspicious sources.

Red Hat statement

Moderate: A heap-based out-of-bounds read flaw in libtheora's AVI parser can lead to a denial-of-service or information leak. Exploitation requires a local attacker to trick a user into opening a specially crafted AVI file.

Red Hat mitigation

To mitigate this issue, users should avoid opening untrusted AVI files. Exercise caution when handling AVI files from unknown or suspicious sources.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 6, 2026
Updated May 1, 2026
Reserved Apr 6, 2026
CISA Vulnrichment
Updated Apr 6, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 6, 2026