Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffinput::readimg() allocate a temporary scanline from m_header.rgba_count but copy from it using m_header.pixel_bytes(), whose stride also includes z-buffer bytes. the oversized memcpy reads beyond the temporary heap buffer and copies adjacent memory into the output image, resulting in a crash or disclosure of adjacent heap data. The affected implementation is identified by src/iff.imageio/iffinput.cpp, IffInput::readimg(), m_header.rgba_count, and m_header.pixel_bytes(), which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory disclosure or crash via heap overread
Action: Apply patch
AI Analysis

Impact

OpenImageIO contains a heap‑buffer overread when reading an uncompressed 16‑bit iff image that also contains a z‑buffer. The code allocates a temporary scanline based on the number of RGBA channels but copies data using a stride that includes the z‑buffer bytes, causing memcpy to read beyond the allocated buffer. This flaw is identified as CWE‑125 and can lead to a crash or disclosure of adjacent heap memory. The impact is a local memory disclosure or denial of service if an attacker controls the image file.

Affected Systems

The vulnerability affects the AcademySoftwareFoundation OpenImageIO library prior to release versions 3.0.20.0, 3.1.15.0, and 3.2.0.3‑beta1.

Risk and Exploitability

The CVSS score is 6.1, indicating a moderate severity. The EPSS score is <1%, indicating a very low but non‑zero exploitation probability. The flaw is not listed in CISA's KEV catalog, and no exploits have been reported. Based on the description, it is inferred that a local or remote attacker could supply a crafted iff image to a system that runs OpenImageIO. An attacker could gain information disclosure or cause a denial‑of‑service condition by triggering the overread.

Generated by OpenCVE AI on September 19, 2026 at 18:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update OpenImageIO to at least version 3.0.20.0, 3.1.15.0, or 3.2.0.3‑beta1 to apply the vendor supplied fix.
  • If an upgrade is not feasible, avoid processing uncompressed 16‑bit iff images containing z‑buffers with OpenImageIO, or limit image processing to trusted sources only.
  • Implement input validation to detect and reject oversized or malformed iff images before passing them to OpenImageIO.

Generated by OpenCVE AI on September 19, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffinput::readimg() allocate a temporary scanline from m_header.rgba_count but copy from it using m_header.pixel_bytes(), whose stride also includes z-buffer bytes. the oversized memcpy reads beyond the temporary heap buffer and copies adjacent memory into the output image, resulting in a crash or disclosure of adjacent heap data. The affected implementation is identified by src/iff.imageio/iffinput.cpp, IffInput::readimg(), m_header.rgba_count, and m_header.pixel_bytes(), which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
Title OpenImageIO: Heap-buffer-overread in IffInput::readimg() when ZBUFFER flag is set
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:41:48.491Z

Reserved: 2026-07-07T18:49:15.607Z

Link: CVE-2026-59956

cve-icon Vulnrichment

Updated: 2026-09-18T17:41:42.807Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:07.290

Modified: 2026-09-29T18:56:57.197

Link: CVE-2026-59956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses