Heap Out-of-Bounds Read in OpenImageIO Affecting Various Versions
CVE-2026-63420
5.5MEDIUM
What is CVE-2026-63420?
A vulnerability in OpenImageIO allows an indexed PSD with transparency metadata to create fewer stored channel buffers than specified. When certain features are enabled, this discrepancy permits an out-of-bounds read in the psdinput::read_native_scanline function, leading to a potential process crash. This issue can be exploited when using versions prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.
Affected Version(s)
OpenImageIO < 3.0.21.0 < 3.0.21.0
OpenImageIO >= 3.1.0.0, < 3.1.16.0 < 3.1.0.0, 3.1.16.0
OpenImageIO >= 3.2.0.0-dev, < 3.2.0.3-beta1 < 3.2.0.0-dev, 3.2.0.3-beta1
