CVE-2026-43907
published 2026-05-14CVE-2026-43907: OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and…
PriorityP347high8.3CVSS 3.1
AVNACLPRNUIRSUCLIHAH
EPSS
0.37%
29.3th percentile
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer overflow in QueryRGBBufferSizeInternal() in DPXColorConverter.cpp leads to a heap-based out-of-bounds write when processing crafted DPX image files. The function computes buffer sizes using 32-bit signed integer arithmetic with negative multipliers (e.g., pixels * -3 * bytes for kCbYCr descriptors and pixels * -4 * bytes for kABGR descriptors), where a negative result is used as an in-band signal that no separate buffer is needed. When the pixel count is sufficiently large, the multiplication overflows INT_MIN and wraps to a small positive value. The caller in dpxinput.cpp interprets this positive value as a required buffer size, allocates an undersized heap buffer via m_decodebuf.resize(), and then writes the full image data into it via fread, resulting in a heap buffer overflow. An attacker can exploit this by crafting a DPX file that triggers the overflow, causing a denial of service (crash) or potentially arbitrary code execution through heap corruption in any application that reads pixel data using OpenImageIO. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| academysoftwarefoundation | openimageio | < 3.0.18.0 | 3.0.18.0 |
| academysoftwarefoundation | openimageio | — | — |
| openimageio | openimageio | < 3.0.18.0 | 3.0.18.0 |
| openimageio | openimageio | — | — |
| openimageio | openimageio | >= 3.1.4.0 < 3.1.13.0 | 3.1.13.0 |
| ubuntu | openimageio | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0 QueryRGBBufferSizeInternal integer overflow (GHSA-cq46-hp4h-cvfr / Nessus ID 314939)
vuldb·2026-05-16·CVSS 8.3
CVE-2026-43907 [HIGH] AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0 QueryRGBBufferSizeInternal integer overflow (GHSA-cq46-hp4h-cvfr / Nessus ID 314939)
A vulnerability, which was classified as critical, has been found in AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0. Impacted is the function QueryRGBBufferSizeInternal. This manipulation causes integer overflow.
This vulnerability appears as CVE-2026-43907. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
Ubuntu
OpenImageIO vulnerabilities
vendor_ubuntu·2026-06-16·CVSS 7.8
CVE-2026-43903 [HIGH] OpenImageIO vulnerabilities
Title: OpenImageIO vulnerabilities
Summary: Several security issues were fixed in OpenImageIO.
It was discovered that OpenImageIO incorrectly performed bounds
checking when processing SGI files. An attacker could possibly
use this issue to cause a denial of service or execute arbitrary
code. (CVE-2026-43903)
It was discovered that OpenImageIO incorrectly handled run-length
encoding when processing Softimage PIC files. An attacker
could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-43904)
It was discovered that OpenImageIO incorrectly validated subimage
metadata when processing HEIF files. An attacker could
possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu
24.04 LT
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [epel-all]
bugzilla·2026-05-15·CVSS 8.3
CVE-2026-43907 [HIGH] CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [epel-all]
CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-43907 OpenImageIO2.5: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [fedora-all]
bugzilla·2026-05-15·CVSS 8.3
CVE-2026-43907 [HIGH] CVE-2026-43907 OpenImageIO2.5: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [fedora-all]
CVE-2026-43907 OpenImageIO2.5: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [fedora-all]
bugzilla·2026-05-15·CVSS 8.3
CVE-2026-43907 [HIGH] CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [fedora-all]
CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files
bugzilla·2026-05-14·CVSS 8.3
CVE-2026-43907 [HIGH] CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files
CVE-2026-43907 OpenImageIO: OpenImageIO: Arbitrary code execution or denial of service via crafted DPX image files
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer overflow in QueryRGBBufferSizeInternal() in DPXColorConverter.cpp leads to a heap-based out-of-bounds write when processing crafted DPX image files. The function computes buffer sizes using 32-bit signed integer arithmetic with negative multipliers (e.g., pixels * -3 * bytes for kCbYCr descriptors and pixels * -4 * bytes for kABGR descriptors), where a negative result is used as an in-band signal that no separate buffer is needed. When the pixel count is sufficiently large, the multiplication overflo
2026-05-14
Published