Executive brief
OpenImageIO is an image processing library used in visual effects and animation workflows. A heap overflow vulnerability in TIFF file parsing allows attackers to crash the application or potentially execute arbitrary code by providing a specially crafted 1-bit CMYK TIFF file that triggers an out-of-bounds memory write during image decoding.
Technical details
A heap buffer overflow exists in TIFFInput::read_native_scanline_locked() when processing 1-bit contiguous CMYK TIFF files with PHOTOMETRIC_SEPARATED color space. The vulnerability occurs because bit_convert() writes 8-bit expanded values to a smaller bit-packed buffer, causing out-of-bounds writes and heap corruption. The issue requires no authentication or user interaction beyond opening a malicious TIFF file; it is fixed in version 3.1.16.0.
Affected products
- Academy Software Foundation OpenImageIO prior to 3.1.16.0
Timeline
- 2026-07-04: patched: Fix merged in commit 6e9b86e
- 2026-09-18: disclosed