Executive brief
OpenImageIO is a widely-used image processing library for VFX and animation workflows. A heap buffer over-read vulnerability in IFF image file parsing can cause application crashes or leak sensitive data from adjacent memory when processing specially crafted 16-bit IFF images with z-buffers, potentially exposing confidential information from the rendering process.
Technical details
A buffer size mismatch in iffinput.cpp's readimg() function allocates a temporary scanline buffer based on rgba_count but copies data using pixel_bytes() stride, which includes z-buffer bytes for 16-bit uncompressed IFF images. This causes memcpy to read beyond the allocated buffer. The vulnerability requires opening a malicious IFF file and affects versions prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1.
Affected products
- Academy Software Foundation OpenImageIO prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1
Timeline
- 2026-09-18: disclosed: CVE-2026-59956 published
- 2026-06-27: patched: Fix merged in commit f01bd16