Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is processed during output close. gifsplitpalette() computes numpixels multiplied by the palette partition width in signed 32-bit arithmetic; a large image overflows that intermediate, corrupts subpixelsa, and drives an out-of-bounds read while building the gif palette, resulting in a process crash and denial of service. The affected implementation is identified by src/gif.imageio/gif.h, GifSplitPalette(), numPixels, subPixelsA, GIFOutput, and truncated TGA input, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Published: 2026-09-18
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Process Crash)
Action: Apply patch
AI Analysis

Impact

OpenImageIO, a widely used image processing library, has a signed integer overflow in the conversion from TGA to GIF images. A truncated TGA file triggers the gifsplitpalette() routine, where the product computes a pixel count multiplied by a palette width using signed 32‑bit arithmetic. The overflow corrupts internal structures and results in an out‑of‑bounds read during the creation of the GIF palette, causing a segmentation fault and terminating the process. The impact is a denial‑of‑service condition when the vulnerable library processes malicious input.

Affected Systems

The vulnerability affects Academy Software Foundation’s OpenImageIO version entries prior to 3.0.21.0, 3.1.16.0, and the pre‑release 3.2.0.3-beta1. Any deployment that still uses those releases and processes TGA images is potentially susceptible.

Risk and Exploitability

The CVSS score of 5.5 places the vulnerability in the moderate severity range. The EPSS score is less than 1%, indicating a low exploitation probability. The vulnerability has not been listed in CISA’s KEV catalog. While no proven exploit is disclosed, the known attack involves supplying a crafted TGA file that triggers a crash during image conversion. No additional network access requirements are stated, so the likely attack vector is the ingestion of a malicious TGA file by a local or remote image processing workflow.

Generated by OpenCVE AI on September 19, 2026 at 17:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to version 3.0.21.0, 3.1.16.0, or later (e.g., 3.2.0.3-beta1).
  • If an upgrade is not immediately possible, vet all TGA files for truncation or corrupted headers before passing them to OpenImageIO; avoid passing untrusted TGA input when possible.
  • Implement monitoring for segmentation faults or process crashes associated with OpenImageIO and raise alerts to detect exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:*
cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is processed during output close. gifsplitpalette() computes numpixels multiplied by the palette partition width in signed 32-bit arithmetic; a large image overflows that intermediate, corrupts subpixelsa, and drives an out-of-bounds read while building the gif palette, resulting in a process crash and denial of service. The affected implementation is identified by src/gif.imageio/gif.h, GifSplitPalette(), numPixels, subPixelsA, GIFOutput, and truncated TGA input, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Title OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV
Weaknesses CWE-125
CWE-190
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:50:44.328Z

Reserved: 2026-07-23T18:15:14.580Z

Link: CVE-2026-65969

cve-icon Vulnrichment

Updated: 2026-09-18T19:30:29.183Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:08.433

Modified: 2026-09-29T18:55:35.733

Link: CVE-2026-65969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses