Sploitus

CVE-2026-5673

No indexed exploits for CVE-2026-5673 yet

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.

Affected products
Libtheora
Xiph Theora
All versions
Redhat Enterprise Linux
= 6.0, 7.0, 8.0, 9.0, 10.0
CVSS 3.1
7.1 HIGH
EPSS
0.2% (8th percentile)
Weakness
CWE-125
NVD status
Analyzed
Published
2026-04-06

Workaround

To mitigate this issue, users should avoid opening untrusted AVI files. Exercise caution when handling AVI files from unknown or suspicious sources.

CVE-2026-5673 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-5673 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-5673 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.