CVE-2024-55195Allocation of Resources Without Limits or Throttling in Openimageio

Severity
7.5HIGHNVD
EPSS
0.1%
top 80.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateJan 24

Description

An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (DoS) when the program to requests to allocate too much space.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

debiandebian/openimageio< openimageio 2.5.18.0+dfsg-1 (forky)
Debianopenimageio/openimageio< 2.5.18.0+dfsg-1+1

🔴Vulnerability Details

2
GHSA
GHSA-mrx2-mvwr-fg6v: An allocation-size-too-big bug in the component /imagebuf2025-01-24
OSV
CVE-2024-55195: An allocation-size-too-big bug in the component /imagebuf2025-01-23

📋Vendor Advisories

1
Debian
CVE-2024-55195: openimageio - An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3....2024