Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of its tile width can trigger an overflow when a caller reads a partial edge-tile rectangle. openexrinput::read_native_tiles() copies each row into the caller buffer using the padded whole-tile scanline_stride rather than user_scanline_bytes for the requested rectangle, resulting in a heap out-of-bounds write and memory corruption. The affected implementation is identified by src/openexr.imageio/exrinput.cpp, OpenEXRInput::read_native_tiles(), partial edge tile, user_scanline_bytes, and scanline_stride, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

An OpenImageIO OpenEXR plugin bug causes a heap out‑of‑bounds write when a caller reads a partial edge tile from a tiled OpenEXR image whose total width is not an exact multiple of the tile width. The read routine copies rows using the padded whole‑tile stride instead of the user‑specified stride, corrupting adjacent memory. This memory corruption can potentially lead to arbitrary code execution or a crash depending on how the corrupted data is later used.

Affected Systems

Academy Software Foundation’s OpenImageIO library is affected when its version is earlier than 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1. Any application that bundles one of these vulnerable releases and processes tiled OpenEXR files with widths not divisible by the tile width is at risk.

Risk and Exploitability

The CVSS score of 7.8 classifies this vulnerability as high severity, and it is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a specially crafted OpenEXR file that contains a partially overlapped edge tile. Therefore the threat primarily targets systems that open potentially untrusted images via OpenImageIO, either locally or from remote sources. Public exploits are not reported in the provided data. The EPSS score is < 1%, indicating a low probability of exploitation.

Generated by OpenCVE AI on September 19, 2026 at 18:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to version 3.0.21.0, 3.1.16.0, 3.2.0.3‑beta1, or any newer release that includes the fix.
  • Ensure that the application uses the updated library before processing any OpenEXR files.
  • If an immediate upgrade is not possible, validate or reject OpenEXR files whose width is not a multiple of the tile width, or process the images in a sandboxed environment to contain any potential heap corruption.

Generated by OpenCVE AI on September 19, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple of its tile width can trigger an overflow when a caller reads a partial edge-tile rectangle. openexrinput::read_native_tiles() copies each row into the caller buffer using the padded whole-tile scanline_stride rather than user_scanline_bytes for the requested rectangle, resulting in a heap out-of-bounds write and memory corruption. The affected implementation is identified by src/openexr.imageio/exrinput.cpp, OpenEXRInput::read_native_tiles(), partial edge tile, user_scanline_bytes, and scanline_stride, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Title OpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds write
Weaknesses CWE-122
CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:50:51.258Z

Reserved: 2026-07-16T19:20:28.988Z

Link: CVE-2026-63422

cve-icon Vulnrichment

Updated: 2026-09-18T19:24:32.622Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:07.987

Modified: 2026-09-29T18:56:15.287

Link: CVE-2026-63422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses