Impact
An OpenImageIO OpenEXR plugin bug causes a heap out‑of‑bounds write when a caller reads a partial edge tile from a tiled OpenEXR image whose total width is not an exact multiple of the tile width. The read routine copies rows using the padded whole‑tile stride instead of the user‑specified stride, corrupting adjacent memory. This memory corruption can potentially lead to arbitrary code execution or a crash depending on how the corrupted data is later used.
Affected Systems
Academy Software Foundation’s OpenImageIO library is affected when its version is earlier than 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1. Any application that bundles one of these vulnerable releases and processes tiled OpenEXR files with widths not divisible by the tile width is at risk.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity, and it is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a specially crafted OpenEXR file that contains a partially overlapped edge tile. Therefore the threat primarily targets systems that open potentially untrusted images via OpenImageIO, either locally or from remote sources. Public exploits are not reported in the provided data. The EPSS score is < 1%, indicating a low probability of exploitation.
OpenCVE Enrichment