Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted cineon image can declare unsupported component bit depth 26. cineoninput::open() maps it to a 32-bit imagespec, but libcineon maps the unsupported depth to an 8-byte value, so cineoninput::read_native_scanline() causes attacker-controlled data to be written beyond the 4-byte-per-pixel caller buffer, resulting in a heap out-of-bounds write and memory corruption. The affected implementation is identified by src/cineon.imageio/cineoninput.cpp, CineonInput::open(), CineonInput::read_native_scanline(), ComponentDataSize(), bit depth 26, and ImageSpec, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Heap out-of-bounds write causing memory corruption
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a heap out-of-bounds write triggered when the Cineon input reader processes images that declare an unsupported 26-bit component depth. The bug occurs because cineoninput::open() maps the depth to a 32‑bit Imagespec while libcineon translates it to an 8‑byte value, causing cineoninput::read_native_scanline() to write beyond the 4‑byte‑per‑pixel buffer supplied by the caller. This results in memory corruption and, per the CWE‑787 classification, could enable an attacker to execute arbitrary code or cause a denial of service.

Affected Systems

Affected is the Academy Software Foundation's OpenImageIO library used for reading, writing, and manipulating image files in VFX and animation workflows. Versions older than 3.0.21.0, 3.1.16.0, and 3.2.0.3‑beta1 are vulnerable. Patch releases 3.0.21.0, 3.1.16.0, and 3.2.0.3‑beta1 contain the fix.

Risk and Exploitability

The CVSS base score is 8.3, indicating a high severity vulnerability. The EPSS score of 0.00238 (less than 1%) indicates a very low exploitation probability. The CVE is not listed in CISA KEV, suggesting no known active exploitation at the time of this analysis. The likely attack vector is a crafted Cineon image supplied to any component that loads images via OpenImageIO. If an attacker can supply such a file, the memory corruption could be leveraged to gain arbitrary code execution or crash an application. Due to the lack of a publicly known exploit and the need for the attacker to supply a specific image file, the overall risk to unprotected systems is high but primarily limited to uses of OpenImageIO in image ingestion workflows.

Generated by OpenCVE AI on September 19, 2026 at 18:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to at least version 3.0.21.0, 3.1.16.0, or 3.2.0.3‑beta1
  • Restart any services or applications that use OpenImageIO after the upgrade to ensure the new library is loaded
  • Add input validation to reject images that declare unsupported bit depths or non‑standard component formats as an additional safeguard

Generated by OpenCVE AI on September 19, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted cineon image can declare unsupported component bit depth 26. cineoninput::open() maps it to a 32-bit imagespec, but libcineon maps the unsupported depth to an 8-byte value, so cineoninput::read_native_scanline() causes attacker-controlled data to be written beyond the 4-byte-per-pixel caller buffer, resulting in a heap out-of-bounds write and memory corruption. The affected implementation is identified by src/cineon.imageio/cineoninput.cpp, CineonInput::open(), CineonInput::read_native_scanline(), ComponentDataSize(), bit depth 26, and ImageSpec, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Title OpenImageIO: Cineon invalid bit depth heap out-of-bounds write
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T14:48:04.230Z

Reserved: 2026-07-17T14:11:15.482Z

Link: CVE-2026-63638

cve-icon Vulnrichment

Updated: 2026-09-22T14:47:54.227Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:08.283

Modified: 2026-09-29T18:55:45.073

Link: CVE-2026-63638

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses