Junglewise Threat Intelligence

CVE-2026-59181: OpenImageIO buffer overflow in Cineon image parsing

CVE-2026-59181 · Severity: medium · CVSS 6.1 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a media processing library used in film and animation production for reading and writing image files. A crafted Cineon image file can trigger a buffer overflow in the parser, allowing an attacker to corrupt memory and crash the application when processing a malicious file. This could disrupt VFX pipelines or provide a foothold for further exploitation.

Technical details

A stack buffer overflow exists in cineoninput.cpp's CineonInput::open() function, where a user-supplied numberOfElements value from a malicious Cineon file is used as a loop bound without validation against the format's maximum of 8, causing writes beyond the fixed-size strings[8] array. An attacker can craft a Cineon image file with an oversized numberOfElements to trigger memory corruption and denial of service. The vulnerability is fixed by adding bounds checking on the numberOfElements value.

Affected products

  • Academy Software Foundation OpenImageIO prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1

Timeline

  • 2026-09-18: disclosed
  • 2026-06-27: patched: Fix merged in commit 908f22f5528e88e5e96184c194caa26b54b2b85f

References

Related threats