CVE-2026-43908
published 2026-05-14CVE-2026-43908: OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.37%
29.4th percentile
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression i * 3 inside ConvertCbYCrYToRGB() causes the function to compute a large negative pointer offset into the output buffer, producing an out-of-bounds write that crashes the process. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| academysoftwarefoundation | openimageio | < 3.0.18.0 | 3.0.18.0 |
| academysoftwarefoundation | openimageio | — | — |
| openimageio | openimageio | < 3.0.18.0 | 3.0.18.0 |
| openimageio | openimageio | — | — |
| openimageio | openimageio | — | — |
| openimageio | openimageio | >= 3.1.4.0 < 3.1.13.0 | 3.1.13.0 |
| ubuntu | openimageio | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0 ConvertCbYCrYToRGB integer overflow (GHSA-2jr5-q49v-3858 / Nessus ID 314938)
vuldb·2026-05-16·CVSS 8.8
CVE-2026-43908 [HIGH] AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0 ConvertCbYCrYToRGB integer overflow (GHSA-2jr5-q49v-3858 / Nessus ID 314938)
A vulnerability labeled as critical has been found in AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0. This vulnerability affects the function ConvertCbYCrYToRGB. Executing a manipulation can lead to integer overflow.
This vulnerability is tracked as CVE-2026-43908. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
Ubuntu
OpenImageIO vulnerabilities
vendor_ubuntu·2026-06-16·CVSS 7.8
CVE-2026-43903 [HIGH] OpenImageIO vulnerabilities
Title: OpenImageIO vulnerabilities
Summary: Several security issues were fixed in OpenImageIO.
It was discovered that OpenImageIO incorrectly performed bounds
checking when processing SGI files. An attacker could possibly
use this issue to cause a denial of service or execute arbitrary
code. (CVE-2026-43903)
It was discovered that OpenImageIO incorrectly handled run-length
encoding when processing Softimage PIC files. An attacker
could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-43904)
It was discovered that OpenImageIO incorrectly validated subimage
metadata when processing HEIF files. An attacker could
possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu
24.04 LT
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow [fedora-all]
bugzilla·2026-05-15·CVSS 8.8
CVE-2026-43908 [HIGH] CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow [fedora-all]
CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow [epel-all]
bugzilla·2026-05-15·CVSS 8.8
CVE-2026-43908 [HIGH] CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow [epel-all]
CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-43908 OpenImageIO2.5: OpenImageIO: Denial of Service via integer overflow [fedora-all]
bugzilla·2026-05-15·CVSS 8.8
CVE-2026-43908 [HIGH] CVE-2026-43908 OpenImageIO2.5: OpenImageIO: Denial of Service via integer overflow [fedora-all]
CVE-2026-43908 OpenImageIO2.5: OpenImageIO: Denial of Service via integer overflow [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow
bugzilla·2026-05-14·CVSS 8.8
CVE-2026-43908 [HIGH] CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow
CVE-2026-43908 OpenImageIO: OpenImageIO: Denial of Service via integer overflow
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression i * 3 inside ConvertCbYCrYToRGB() causes the function to compute a large negative pointer offset into the output buffer, producing an out-of-bounds write that crashes the process. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0.
2026-05-14
Published