Junglewise Threat Intelligence

CVE-2026-63422: OpenImageIO heap overflow in OpenEXR partial tile reading

CVE-2026-63422 · Severity: high · CVSS 7.8 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a widely-used image processing library for VFX and animation workflows. A vulnerability in its OpenEXR file reader can cause heap buffer overflow when processing specially crafted tiled EXR images whose width is not a multiple of the tile size, potentially leading to memory corruption, application crashes, or arbitrary code execution.

Technical details

The vulnerability exists in OpenImageIO's read_native_tiles() function, which incorrectly uses tile-padded scanline stride instead of the user's requested rectangle width when copying partial edge tiles, resulting in out-of-bounds heap writes. The flaw affects tiled OpenEXR images with non-tile-aligned dimensions when read_native_tiles() is called. An attacker can craft a malicious EXR file to trigger this overflow; no authentication or special privileges are required, only that the application reads the image via the vulnerable code path.

Affected products

  • Academy Software Foundation OpenImageIO before 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1

Timeline

  • 2026-07-15: patched: Fix committed to main branch
  • 2026-09-18: disclosed

References

Related threats