Description
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFInput::read_native_scanlines() return through an error path while asynchronous strip-decompression work remains queued. Because task_set is declared before ok and compressed_scratch, those captured objects are destroyed before the task-set destructor waits, allowing worker tasks to use stale stack and heap storage, resulting in a use-after-scope crash and denial of service. The affected implementation is identified by src/tiff.imageio/tiffinput.cpp, TIFFInput::read_native_scanlines(), task_set, ok, compressed_scratch, and uncompress_one_strip(), which define the relevant source path, functions, state, and trigger. This issue is fixed in 3.1.16.0.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service due to use‑after‑scope crash
Action: Immediate Patch
AI Analysis

Impact

A crafted ZIP‑compressed TIFF file that is processed with TIFF multithreading enabled triggers a use‑after‑scope crash inside TIFFInput::read_native_scanlines(). The crash occurs after an error path is taken while asynchronous strip‑decompression work is still queued; task_set is defined before ok and compressed_scratch, causing those objects to be destroyed before the task_set destructor waits. Worker threads then access stale stack or heap storage, executing code that has already gone out of scope. The result is an immediate denial of service due to a crash, aligning with CWE‑825 (Use After Return, Use After Scope).

Affected Systems

The vulnerability affects the OpenImageIO library distributed by the Academy Software Foundation. All releases prior to 3.1.16.0 are susceptible, regardless of the exact sub‑release, through the TIFF input module (tiffinput.cpp). Any deployment that relies on this library to read TIFF images—especially in VFX or animation pipelines—is potentially impacted.

Risk and Exploitability

With a CVSS score of 5.3, the vulnerability carries moderate severity. The EPSS score is 0.00373, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or remote image ingestion; an attacker who can supply a malicious TIFF file to the image processing pipeline can trigger the crash. The exploitation requires the TIFF multithreading feature to be enabled, which is a common configuration in high‑throughput rendering contexts.

Generated by OpenCVE AI on September 19, 2026 at 18:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenImageIO to version 3.1.16.0 or later
  • If an upgrade is not immediately possible, avoid loading untrusted ZIP‑compressed TIFF files into the application or disable the multithreaded scanline feature if the library configuration permits
  • Apply additional process isolation—run image processing in a sandbox or separate container—to contain a potential crash and prevent denial of service to the entire system

Generated by OpenCVE AI on September 19, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Openimageio
Openimageio openimageio
CPEs cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:*
Vendors & Products Openimageio
Openimageio openimageio

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Academysoftwarefoundation
Academysoftwarefoundation openimageio
Vendors & Products Academysoftwarefoundation
Academysoftwarefoundation openimageio

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFInput::read_native_scanlines() return through an error path while asynchronous strip-decompression work remains queued. Because task_set is declared before ok and compressed_scratch, those captured objects are destroyed before the task-set destructor waits, allowing worker tasks to use stale stack and heap storage, resulting in a use-after-scope crash and denial of service. The affected implementation is identified by src/tiff.imageio/tiffinput.cpp, TIFFInput::read_native_scanlines(), task_set, ok, compressed_scratch, and uncompress_one_strip(), which define the relevant source path, functions, state, and trigger. This issue is fixed in 3.1.16.0.
Title OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::read_native_scanlines`
Weaknesses CWE-825
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Academysoftwarefoundation Openimageio
Openimageio Openimageio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T16:43:54.088Z

Reserved: 2026-07-23T18:15:14.580Z

Link: CVE-2026-65970

cve-icon Vulnrichment

Updated: 2026-09-18T16:42:26.559Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T16:17:08.590

Modified: 2026-09-29T18:55:22.617

Link: CVE-2026-65970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:30:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference