Memory Management Flaw in OpenImageIO Affects Image Processing Software by Academy Software Foundation
CVE-2026-59956

6.1MEDIUM

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-59956?

A memory management vulnerability in OpenImageIO prior to versions 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1 allows for an oversized memcpy operation on uncompressed 16-bit iff images with a z-buffer, which can lead to crashes or potential disclosure of adjacent memory. This issue originates from the mishandling of pixel stride calculations in the readimg function, impacting the reliability of image processing and necessitating updates to ensure data integrity.

Affected Version(s)

OpenImageIO < 3.0.20.0 < 3.0.20.0

OpenImageIO >= 3.1.0.0, < 3.1.15.0 < 3.1.0.0, 3.1.15.0

OpenImageIO >= 3.2.0.0-dev, < 3.2.0.3-beta1 < 3.2.0.0-dev, 3.2.0.3-beta1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.