CVE-2026-5673
A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit this by tricking a user into opening a specially crafted AVI file containing a truncated header sub-chunk. This could lead to a denial-of-service (application crash) or potentially leak sensitive information from the heap.
- Affected products
- Libtheora
- Xiph Theora
- All versions
- Redhat Enterprise Linux
- = 6.0, 7.0, 8.0, 9.0, 10.0
- CVSS 3.1
- 7.1 HIGH
- EPSS
- 0.2% (8th percentile)
- Weakness
- CWE-125
- NVD status
- Analyzed
- Published
- 2026-04-06
Workaround
To mitigate this issue, users should avoid opening untrusted AVI files. Exercise caution when handling AVI files from unknown or suspicious sources.
No indexed exploits for CVE-2026-5673 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-5673 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.