Executive brief
OpenImageIO is a VFX/animation image processing library that reads and writes image files in many formats. A 32-bit integer overflow in GIF output processing, triggered by processing truncated TGA files with large images, can cause the application to crash and deny service. An attacker could exploit this by providing a specially crafted truncated TGA file to trigger the vulnerability.
Technical details
The GifSplitPalette() function in OpenImageIO computes `numPixels * (splitElt - firstElt)` in signed 32-bit arithmetic, causing integer overflow for images larger than approximately 16.9 megapixels (e.g., 4117×4117). This overflow produces a bogus negative or garbage split count that drives out-of-bounds array indexing during GIF palette construction. The vulnerability is triggered when processing a truncated TGA file that leaves a pending GIF frame to be processed during output close, resulting in a process crash.
Affected products
- Academy Software Foundation OpenImageIO before 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1
Timeline
- 2026-09-18: disclosed: CVE-2026-65969 published
- 2026-07-06: patched: Fix merged in version 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1