CVE-2026-65970
Description
A flaw was found in OpenImageIO, a toolset for image file manipulation. A remote attacker could exploit this vulnerability by providing a specially crafted ZIP-compressed TIFF image file. When processed with TIFF multithreading enabled, the software can prematurely release memory while background tasks are still active. This leads to worker tasks attempting to access deallocated memory, resulting in a system crash and a denial of service.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
To mitigate this issue, avoid processing untrusted ZIP-compressed TIFF images with applications that use OpenImageIO, particularly when TIFF multithreading is enabled. Restricting image input to trusted sources can reduce the risk of exploitation. Consider sandboxing applications that process untrusted image data to limit the impact of potential crashes.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Memory
If the expired pointer is used in a read operation, an attacker might be able to control data read in by the application.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
If the expired pointer references a memory location that is not accessible to the product, or points to a location that is "malformed" (such as NULL) or larger than expected by a read or write operation, then a crash may occur.
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands
If the expired pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.