Junglewise Threat Intelligence

CVE-2026-43904: OpenImageIO heap overflow in Softimage PIC RLE decoder

CVE-2026-43904 · Severity: high · CVSS 7.8 · Published 2026-05-14

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a widely used library in the visual effects and animation industry for processing various image file formats. A vulnerability in how the library handles Softimage PIC files allows a specially crafted image to crash the application or potentially allow an attacker to take control of the system. This occurs when a user opens a malicious image file, which could lead to data theft or service disruptions in production environments.

Technical details

A heap-based buffer overflow exists in OpenImageIO's Softimage PIC image decoder due to improper bounds checking of Run-Length Encoding (RLE) data. Specifically, in softimageinput.cpp, the 'longCount' variable (a uint16 provided by the file) is not clamped to the remaining scanline width in the mixed RLE and pure RLE processing paths. An attacker can provide a crafted .pic file with an RLE length up to 65535 bytes, exceeding the allocated scanline buffer. Exploitation requires a user to open the malicious file and can result in arbitrary code execution or a denial-of-service (crash). The issue is resolved in versions 3.0.18.0 and 3.1.13.0 by implementing proper clamping using std::min.

Affected products

  • Academy Software Foundation OpenImageIO < 3.0.18.0, < 3.1.13.0

Timeline

  • 2026-05-03: advisory: GitHub advisory published by maintainers
  • 2026-05-14: disclosed: CVE published to NVD

References

Related threats