Impact
A heap out‑of‑bounds write occurs when OpenImageIO’s IFF zbuffer tile reader copies pixel data using a 32‑bit internal size while the caller supplies a 16‑bit tile buffer. If a read fails, partially initialized data can be written into the undersized caller buffer, corrupting heap memory. This memory corruption could allow an attacker to execute arbitrary code, although the exact consequence depends on the execution environment.
Affected Systems
Academy Software Foundation’s OpenImageIO versions before 3.0.21.0, 3.1.16.0, and 3.2.0.3‑beta1 are affected. VFX and animation pipelines that process zbuffer‑only tiled IFF files using these releases are at risk; all earlier releases contain the same flaw.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of approximately 0.2% reflects a low but non‑zero likelihood of exploitation and the vulnerability is not listed in CISA KEV. The likely attack vector involves delivery of a malicious IFF file, potentially through local or remote means; the out‑of‑bounds write may allow privilege escalation or code execution in environments lacking strict sandboxing.
OpenCVE Enrichment