Impact
OpenImageIO, a cross‑platform toolkit for image file handling, contains a flaw in the TIFF input path that allows a specially crafted 1‑bit CMYK TIFF file to trigger a heap out‑of-bounds write. When the file is processed, tiffinput::read_native_scanline_locked() calls tiffinput::bit_convert() to expand 1‑bit data into 8‑bit values. The caller allocates a bit‑packed buffer for the former, but the routine writes one expanded byte per input value into that smaller buffer, corrupting adjacent heap memory. This memory corruption can lead to crashes or data loss; while arbitrary code execution is a potential consequence given the nature of the overflow, it is not explicitly stated in the CVE description and is therefore inferred.
Affected Systems
The vulnerability affects the OpenImageIO toolset produced by the Academy Software Foundation. Any version of OpenImageIO older than 3.1.16.0 is susceptible, as the bug was corrected in the 3.1.16.0 release. Users who rely on the TIFF input plugin for processing CMYK data are at risk.
Risk and Exploitability
The CVSS base score of 7.6, combined with an EPSS score of 0.00262 (below 1%), suggests a high but not extreme likelihood of exploitation given the file‑based nature of the attack. Because exploitation occurs when a crafted TIFF file is parsed, the attack vector is local or potentially remote if the software is exposed to untrusted input. The bug is not listed in the CISA KEV catalog, indicating no publicly known widespread attacks yet. Memory corruption of this type can elevate to denial‑of‑service at a minimum; whether it can lead to arbitrary code execution is not confirmed by the description and remains an inferred possibility.
OpenCVE Enrichment