Executive brief
OpenImageIO is a toolset for reading and manipulating image files used in VFX and animation production. A crafted FITS image file with excessive header blocks can trigger a stack overflow in the parsing code, causing the application to crash and resulting in denial of service for any workflow processing untrusted FITS files.
Technical details
The vulnerability is a stack overflow caused by unbounded recursion in FitsInput::read_fits_header() when parsing FITS files with many consecutive 2880-byte header blocks lacking the mandatory END keyword. An attacker can supply a malicious FITS file that exhausts the application stack through recursive parsing calls. The fix converts the recursive implementation to an iterative loop with a maximum limit of 10,000 header blocks.
Affected products
- Academy Software Foundation OpenImageIO before 3.0.20.0, before 3.1.15.0, before 3.2.0.3-beta1
Timeline
- 2026-09-18: disclosed
- 2026-06-20: patched: Fix committed to main branch