Executive brief
OpenImageIO is a library for reading and writing image files used in VFX and animation production. A flaw in the IFF image format decoder can allow attackers to cause memory corruption by providing a specially crafted IFF image file, potentially leading to application crashes or arbitrary code execution.
Technical details
A heap out-of-bounds write vulnerability exists in iffinput::read_native_tile() due to a mismatch between the public ImageSpec tile bytes (16-bit) and internal pixel size (32-bit) for zbuffer-only tiled IFF images. The decoder copies data using m_header.pixel_bytes() instead of imagespec::tile_bytes(true), and failed reads can leave m_buf nonempty, causing partially initialized data to be written to an undersized caller buffer. This can be triggered by providing a malicious IFF file without authentication or special privileges.
Affected products
- Academy Software Foundation OpenImageIO before 3.0.21.0, before 3.1.16.0, before 3.2.0.3-beta1
Timeline
- 2026-09-18: disclosed
- 2026-07-02: patched