Impact
The vulnerability is a heap out-of-bounds write triggered when the Cineon input reader processes images that declare an unsupported 26-bit component depth. The bug occurs because cineoninput::open() maps the depth to a 32‑bit Imagespec while libcineon translates it to an 8‑byte value, causing cineoninput::read_native_scanline() to write beyond the 4‑byte‑per‑pixel buffer supplied by the caller. This results in memory corruption and, per the CWE‑787 classification, could enable an attacker to execute arbitrary code or cause a denial of service.
Affected Systems
Affected is the Academy Software Foundation's OpenImageIO library used for reading, writing, and manipulating image files in VFX and animation workflows. Versions older than 3.0.21.0, 3.1.16.0, and 3.2.0.3‑beta1 are vulnerable. Patch releases 3.0.21.0, 3.1.16.0, and 3.2.0.3‑beta1 contain the fix.
Risk and Exploitability
The CVSS base score is 8.3, indicating a high severity vulnerability. The EPSS score of 0.00238 (less than 1%) indicates a very low exploitation probability. The CVE is not listed in CISA KEV, suggesting no known active exploitation at the time of this analysis. The likely attack vector is a crafted Cineon image supplied to any component that loads images via OpenImageIO. If an attacker can supply such a file, the memory corruption could be leveraged to gain arbitrary code execution or crash an application. Due to the lack of a publicly known exploit and the need for the attacker to supply a specific image file, the overall risk to unprotected systems is high but primarily limited to uses of OpenImageIO in image ingestion workflows.
OpenCVE Enrichment