A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A specially crafted MKV file can cause arbitrary code execution in the context of the current user.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-4022.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "25.0.0" } ] } ]