Impact
OpenImageIO reads PSD files through its psdinput module. A crafted PSD containing an invalid color_mode bypasses normal validation when the oiio:rawcolor or psd:rawdata options are enabled. The psdinput::setup routine then uses the attacker‑controlled value to index fixed color‑mode tables, leading to a global out‑of‑bounds read and possibly an incorrect allocation. This can crash the image‑processing thread or consume excessive memory, resulting in a denial of service. The weakness is a classic out‑of‑bounds read (CWE‑125) combined with an integer handling flaw (CWE‑129).
Affected Systems
The affected software is the Academy Software Foundation’s OpenImageIO library. Versions prior to 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1 contain the vulnerable implementation in src/psd.imageio/psdinput.cpp. Any release older than these specified versions that still accepts PSD files with rawcolor or rawdata enabled is at risk.
Risk and Exploitability
The CVSS score of 5.5 classifies the vulnerability as medium severity. EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog, suggesting no widespread public exploitation has been recorded. The attack vector is inferred to be an image file crafted by an attacker; an OpenImageIO instance must open the file to trigger the failure. A local trusted installation of the library could be affected if it processes untrusted PSD files, but remote exploitation would require the attacker to supply the file to a target that has the library enabled.
OpenCVE Enrichment