Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A zbuffer-only tiled iff is exposed with a 16-bit public imagespec while the decoder retains a 32-bit internal pixel size. iffinput::read_native_tile() copies according to m_header.pixel_bytes() rather than imagespec::tile_bytes(true), and a failed read can leave m_buf nonempty so a later call copies partially initialized data into the undersized caller buffer, resulting in a heap out-of-bounds write and memory corruption. The affected implementation is identified by src/iff.imageio/iffinput.cpp, IffInput::read_native_tile(), ImageSpec::tile_bytes(true), m_header.pixel_bytes(), ZBUFFER, and m_buf, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption (possible Remote Code Execution)
Action: Immediate Patch
AI Analysis

Impact

A heap out‑of‑bounds write occurs when OpenImageIO’s IFF zbuffer tile reader copies pixel data using a 32‑bit internal size while the caller supplies a 16‑bit tile buffer. If a read fails, partially initialized data can be written into the undersized caller buffer, corrupting heap memory. This memory corruption could allow an attacker to execute arbitrary code, although the exact consequence depends on the execution environment.

Affected Systems

Academy Software Foundation’s OpenImageIO versions before 3.0.21.0, 3.1.16.0, and 3.2.0.3‑beta1 are affected. VFX and animation pipelines that process zbuffer‑only tiled IFF files using these releases are at risk; all earlier releases contain the same flaw.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of approximately 0.2% reflects a low but non‑zero likelihood of exploitation and the vulnerability is not listed in CISA KEV. The likely attack vector involves delivery of a malicious IFF file, potentially through local or remote means; the out‑of‑bounds write may allow privilege escalation or code execution in environments lacking strict sandboxing.

Generated by OpenCVE AI on September 19, 2026 at 18:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to a patched release such as 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1 to eliminate the out‑of‑bounds write.
  • If an upgrade cannot be performed immediately, avoid ingesting zbuffer‑only tiled IFF images or validate tile buffer sizes before decoding to protect against memory corruption.
  • Run image processing inside a sandboxed or least‑privileged container to contain potential exploitation until a patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A zbuffer-only tiled iff is exposed with a 16-bit public imagespec while the decoder retains a 32-bit internal pixel size. iffinput::read_native_tile() copies according to m_header.pixel_bytes() rather than imagespec::tile_bytes(true), and a failed read can leave m_buf nonempty so a later call copies partially initialized data into the undersized caller buffer, resulting in a heap out-of-bounds write and memory corruption. The affected implementation is identified by src/iff.imageio/iffinput.cpp, IffInput::read_native_tile(), ImageSpec::tile_bytes(true), m_header.pixel_bytes(), ZBUFFER, and m_buf, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Title OpenImageIO: IFF ZBUFFER tile read writes past caller tile buffer
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:34:05.134Z

Reserved: 2026-07-16T19:20:28.988Z

Link: CVE-2026-63419

cve-icon Vulnrichment

Updated: 2026-09-18T17:33:53.887Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:07.687

Modified: 2026-09-29T18:56:40.093

Link: CVE-2026-63419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses