5.5

CVE-2026-63635

Exploit

OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read and allocation DoS

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal validation when oiio:rawcolor or psd:rawdata is enabled. psdinput::setup() then uses the attacker-controlled value to index fixed color-mode tables, causing a global out-of-bounds read and potentially a bogus allocation, resulting in denial of service. The affected implementation is identified by src/psd.imageio/psdinput.cpp, PSDInput::validate_header(), PSDInput::setup(), oiio:RawColor, psd:RawData, color_mode, and mode_channel_count, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openimageio ≫ Openimageio Version < 3.0.21.0
Openimageio ≫ Openimageio Version >= 3.1.0.0 <= 3.1.16.0
Openimageio ≫ Openimageio Version 3.2.0.0 Update dev
Openimageio ≫ Openimageio Version 3.2.0.2 Update dev
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.047
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-129 Improper Validation of Array Index

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

https://github.com/AcademySoftwareFoundation/OpenImageIO/releases/tag/v3.0.21.0
Release Notes
https://github.com/AcademySoftwareFoundation/OpenImageIO/releases/tag/v3.1.16.0
Release Notes
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-3c8w-9xvm-r6gf
Vendor Advisory
Exploit
Mitigation
https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5282
Patch
Issue Tracking
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/50481b0f90932a4675f65f3cc26407139cb9e20e
Patch
https://github.com/user-attachments/files/29539076/poc.zip
Exploit