Junglewise Threat Intelligence

CVE-2026-59956: OpenImageIO heap buffer over-read in IFF image parsing

CVE-2026-59956 · Severity: medium · CVSS 6.1 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a widely-used image processing library for VFX and animation workflows. A heap buffer over-read vulnerability in IFF image file parsing can cause application crashes or leak sensitive data from adjacent memory when processing specially crafted 16-bit IFF images with z-buffers, potentially exposing confidential information from the rendering process.

Technical details

A buffer size mismatch in iffinput.cpp's readimg() function allocates a temporary scanline buffer based on rgba_count but copies data using pixel_bytes() stride, which includes z-buffer bytes for 16-bit uncompressed IFF images. This causes memcpy to read beyond the allocated buffer. The vulnerability requires opening a malicious IFF file and affects versions prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.

Affected products

  • Academy Software Foundation OpenImageIO prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1

Timeline

  • 2026-09-18: disclosed: CVE-2026-59956 published
  • 2026-06-27: patched: Fix merged in commit f01bd16

References

Related threats