Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal validation when oiio:rawcolor or psd:rawdata is enabled. psdinput::setup() then uses the attacker-controlled value to index fixed color-mode tables, causing a global out-of-bounds read and potentially a bogus allocation, resulting in denial of service. The affected implementation is identified by src/psd.imageio/psdinput.cpp, PSDInput::validate_header(), PSDInput::setup(), oiio:RawColor, psd:RawData, color_mode, and mode_channel_count, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

OpenImageIO reads PSD files through its psdinput module. A crafted PSD containing an invalid color_mode bypasses normal validation when the oiio:rawcolor or psd:rawdata options are enabled. The psdinput::setup routine then uses the attacker‑controlled value to index fixed color‑mode tables, leading to a global out‑of‑bounds read and possibly an incorrect allocation. This can crash the image‑processing thread or consume excessive memory, resulting in a denial of service. The weakness is a classic out‑of‑bounds read (CWE‑125) combined with an integer handling flaw (CWE‑129).

Affected Systems

The affected software is the Academy Software Foundation’s OpenImageIO library. Versions prior to 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1 contain the vulnerable implementation in src/psd.imageio/psdinput.cpp. Any release older than these specified versions that still accepts PSD files with rawcolor or rawdata enabled is at risk.

Risk and Exploitability

The CVSS score of 5.5 classifies the vulnerability as medium severity. EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog, suggesting no widespread public exploitation has been recorded. The attack vector is inferred to be an image file crafted by an attacker; an OpenImageIO instance must open the file to trigger the failure. A local trusted installation of the library could be affected if it processes untrusted PSD files, but remote exploitation would require the attacker to supply the file to a target that has the library enabled.

Generated by OpenCVE AI on September 19, 2026 at 17:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to version 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1 or later.
  • If an upgrade is not immediately possible, disable the oiio:rawcolor and psd:rawdata options when parsing PSD files from untrusted sources.
  • Prior to parsing, validate the PSD color_mode field to ensure it matches the list of accepted values, or sandbox the image processing to limit memory usage.

Generated by OpenCVE AI on September 19, 2026 at 17:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Fri, 25 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
References

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal validation when oiio:rawcolor or psd:rawdata is enabled. psdinput::setup() then uses the attacker-controlled value to index fixed color-mode tables, causing a global out-of-bounds read and potentially a bogus allocation, resulting in denial of service. The affected implementation is identified by src/psd.imageio/psdinput.cpp, PSDInput::validate_header(), PSDInput::setup(), oiio:RawColor, psd:RawData, color_mode, and mode_channel_count, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Title OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read and allocation DoS
Weaknesses CWE-125
CWE-129
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:56:40.284Z

Reserved: 2026-07-17T14:11:15.482Z

Link: CVE-2026-63635

cve-icon Vulnrichment

Updated: 2026-09-24T20:56:31.970Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:08.130

Modified: 2026-09-29T18:55:56.597

Link: CVE-2026-63635

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-129

    Improper Validation of Array Index