Impact
A malformed BMP file with an empty palette triggers an out‑of‑bounds read during decoding of an RLE‑compressed scanline in OpenImageIO’s BmpInput::read_native_scanline function, causing the process to crash and denying service to the application or tool that loaded the file. The flaw is an out‑of‑bounds read as documented by CWE‑125 and results in a local denial of service when the vulnerable library processes crafted input.
Affected Systems
The vulnerability affects the OpenImageIO library distributed by AcademySoftwareFoundation. Versions older than 3.0.16.0 and 3.1.11.0 are impacted; the issue was resolved in releases 3.0.16.0 and 3.1.11.0. Users running earlier releases on any supported host platform, such as those linked into oiiotool or other VFX/animation tools, are at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score of less than 1% denotes a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via a crafted BMP file that an application or tool expects to read, so the flaw can be triggered remotely by providing malicious input or locally by an attacker who can influence the input file.
OpenCVE Enrichment