Ad

CVE-2026-65969

MEDIUM CVSS 3.1: 5,5 EPSS 0.17%
Обновлено 23 сентября 2026
Openimageio
Параметр Значение
CVSS 5,5 (MEDIUM)
Тип уязвимости CWE-125 (Чтение за пределами буфера), CWE-190 (Целочисленное переполнение)
Поставщик Openimageio
Публичный эксплойт Нет

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is processed during output close. gifsplitpalette() computes numpixels multiplied by the palette partition width in signed 32-bit arithmetic; a large image overflows that intermediate, corrupts subpixelsa, and drives an out-of-bounds read while building the gif palette, resulting in a process crash and denial of service. The affected implementation is identified by src/gif.imageio/gif.h, GifSplitPalette(), numPixels, subPixelsA, GIFOutput, and truncated TGA input, which define the relevant source path, functions, state, and trigger.

This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.

Характеристики атаки

Способ атаки
Локальный
Нужен локальный доступ
Сложность
Низкая
Легко эксплуатировать
Нужны права
Не требуются
Права не нужны
Участие пользователя
Требуется
Нужно действие пользователя

Последствия

Конфиденциальность
Нет
Нет утечки данных
Целостность
Нет
Нет модификации данных
Доступность
Высокое
Полный отказ в обслуживании

Строка CVSS v3.1