CVE-2026-63419

Description

A flaw was found in OpenImageIO, a toolset for reading, writing, and manipulating image files. When processing specially crafted IFF (Image File Format) ZBUFFER tiles, the iffinput::read_native_tile() function may incorrectly handle pixel data sizes. This can lead to a heap out-of-bounds write, resulting in memory corruption.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

To mitigate this issue, avoid processing untrusted IFF image files with applications that utilize OpenImageIO. If processing untrusted content is unavoidable, ensure that applications using OpenImageIO are run within a sandboxed environment to limit potential impact from memory corruption.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Memory; Execute Unauthorized Code or Commands

Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.

Other

Technical Impact: Unexpected State

Subsequent write operations can produce undefined or unexpected results.

Frequently Asked Questions

Want to get errata notifications? Sign up here.