Impact
A crafted ZIP‑compressed TIFF file that is processed with TIFF multithreading enabled triggers a use‑after‑scope crash inside TIFFInput::read_native_scanlines(). The crash occurs after an error path is taken while asynchronous strip‑decompression work is still queued; task_set is defined before ok and compressed_scratch, causing those objects to be destroyed before the task_set destructor waits. Worker threads then access stale stack or heap storage, executing code that has already gone out of scope. The result is an immediate denial of service due to a crash, aligning with CWE‑825 (Use After Return, Use After Scope).
Affected Systems
The vulnerability affects the OpenImageIO library distributed by the Academy Software Foundation. All releases prior to 3.1.16.0 are susceptible, regardless of the exact sub‑release, through the TIFF input module (tiffinput.cpp). Any deployment that relies on this library to read TIFF images—especially in VFX or animation pipelines—is potentially impacted.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability carries moderate severity. The EPSS score is 0.00373, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or remote image ingestion; an attacker who can supply a malicious TIFF file to the image processing pipeline can trigger the crash. The exploitation requires the TIFF multithreading feature to be enabled, which is a common configuration in high‑throughput rendering contexts.
OpenCVE Enrichment