Junglewise Threat Intelligence

CVE-2026-63638: OpenImageIO heap overflow in cineon image parsing

CVE-2026-63638 · Severity: high · CVSS 8.3 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a widely-used image processing library for VFX and animation workflows. A crafted cineon image file with an unsupported bit depth value can trigger a heap buffer overflow when the library processes it, allowing an attacker to corrupt memory and potentially execute arbitrary code on systems that process untrusted image files.

Technical details

A mismatch between OpenImageIO's bit-depth validation (accepting 1–32) and libcineon's supported depths (only 8, 10, 12, 16, 32, 64) allows a crafted cineon file with an unsupported depth like 26 to pass initial checks and cause a heap out-of-bounds write in CineonInput::read_native_scanline(), when attacker-controlled data is written beyond the caller-allocated 4-byte-per-pixel buffer. The fix tightens validation to reject unsupported bit depths before calling the vulnerable libcineon code.

Affected products

  • Academy Software Foundation OpenImageIO prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1

Timeline

  • 2026-09-18: disclosed: CVE-2026-63638 published
  • 2026-07-06: patched: Fix merged in commit 6f2b2e8 to validate bit depth against libcineon's supported set

References

Related threats