Junglewise Threat Intelligence

CVE-2026-65969: OpenImageIO integer overflow in GIF palette splitting

CVE-2026-65969 · Severity: medium · CVSS 5.5 · Published 2026-09-18

Technologies: Academy Software Foundation OpenImageIO. Vendors: Academy Software Foundation.

Executive brief

OpenImageIO is a VFX/animation image processing library that reads and writes image files in many formats. A 32-bit integer overflow in GIF output processing, triggered by processing truncated TGA files with large images, can cause the application to crash and deny service. An attacker could exploit this by providing a specially crafted truncated TGA file to trigger the vulnerability.

Technical details

The GifSplitPalette() function in OpenImageIO computes `numPixels * (splitElt - firstElt)` in signed 32-bit arithmetic, causing integer overflow for images larger than approximately 16.9 megapixels (e.g., 4117×4117). This overflow produces a bogus negative or garbage split count that drives out-of-bounds array indexing during GIF palette construction. The vulnerability is triggered when processing a truncated TGA file that leaves a pending GIF frame to be processed during output close, resulting in a process crash.

Affected products

  • Academy Software Foundation OpenImageIO before 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1

Timeline

  • 2026-09-18: disclosed: CVE-2026-65969 published
  • 2026-07-06: patched: Fix merged in version 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1

References

Related threats