Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value greater than the format maximum of eight. cineoninput::open() uses that unchecked value as the loop bound while filling the fixed strings[8] array, writing pointers beyond the stack buffer and into adjacent state, resulting in memory corruption and denial of service. The affected implementation is identified by src/cineon.imageio/cineoninput.cpp, CineonInput::open(), numberOfElements, and strings[8], which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via stack buffer overflow
Action: Apply Patch
AI Analysis

Impact

A crafted Cineon file can supply a number of elements greater than the format maximum of eight. The OpenImageIO Cineon reader uses that unchecked value as a loop bound while filling a fixed eight-entry string array, writing pointers beyond the stack buffer and into adjacent memory, which results in memory corruption and a denial of service. This is a classic stack buffer overflow (CWE-121) that violates bounds checking (CWE-787).

Affected Systems

The vulnerable product is OpenImageIO from the Academy Software Foundation. Versions released before 3.0.20.0, before 3.1.15.0, and before 3.2.0.3-beta1 are susceptible when the Cineon input plugin is present.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. EPSS score of 0.00198 indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, so public exploitation is uncertain. The likely attack vector involves a local attacker providing a malicious Cineon file to the application; remote exploitation would require additional means to deliver such a file.

Generated by OpenCVE AI on September 19, 2026 at 18:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to at least version 3.0.20.0, 3.1.15.0, or 3.2.0.3-beta1, which implements bounds checking for the number of elements, addressing the stack overflow and the related CWE identifiers.
  • If an immediate update cannot be performed, restrict the use of Cineon inputs to trusted sources and validate the number of elements before processing to prevent overflows.
  • Monitor the application for crashes or abnormal memory usage, and apply any additional patches or mitigations as they become available.

Generated by OpenCVE AI on September 19, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value greater than the format maximum of eight. cineoninput::open() uses that unchecked value as the loop bound while filling the fixed strings[8] array, writing pointers beyond the stack buffer and into adjacent state, resulting in memory corruption and denial of service. The affected implementation is identified by src/cineon.imageio/cineoninput.cpp, CineonInput::open(), numberOfElements, and strings[8], which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
Title OpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElements
Weaknesses CWE-121
CWE-787
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T16:52:21.863Z

Reserved: 2026-07-02T19:53:48.830Z

Link: CVE-2026-59181

cve-icon Vulnrichment

Updated: 2026-09-18T16:52:15.512Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:07.137

Modified: 2026-09-29T18:57:09.487

Link: CVE-2026-59181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:30:16Z

Weaknesses