Junglewise Threat Intelligence

CVE-2026-63419: OpenImageIO heap out-of-bounds write in IFF decoder

CVE-2026-63419 · Severity: high · CVSS 7.8 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a library for reading and writing image files used in VFX and animation production. A flaw in the IFF image format decoder can allow attackers to cause memory corruption by providing a specially crafted IFF image file, potentially leading to application crashes or arbitrary code execution.

Technical details

A heap out-of-bounds write vulnerability exists in iffinput::read_native_tile() due to a mismatch between the public ImageSpec tile bytes (16-bit) and internal pixel size (32-bit) for zbuffer-only tiled IFF images. The decoder copies data using m_header.pixel_bytes() instead of imagespec::tile_bytes(true), and failed reads can leave m_buf nonempty, causing partially initialized data to be written to an undersized caller buffer. This can be triggered by providing a malicious IFF file without authentication or special privileges.

Affected products

  • Academy Software Foundation OpenImageIO before 3.0.21.0, before 3.1.16.0, before 3.2.0.3-beta1

Timeline

  • 2026-09-18: disclosed
  • 2026-07-02: patched

References

Related threats