PT-2026-41025 · Unknown+2 · Openimageio+2

·

CVE-2026-43906

·

Published

2026-05-14

·

Updated

2026-06-17

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenImageIO versions prior to 3.0.18.0 OpenImageIO versions prior to 3.1.13.0
Description OpenImageIO is a toolset for reading, writing, and manipulating image files for VFX and animation. A heap-based buffer overflow occurs in the HEIF decoder when processing crafted images with a subimage metadata mismatch. This leads to out-of-bounds writes, resulting in memory corruption and potential code execution.
Recommendations Update to version 3.0.18.0. Update to version 3.1.13.0.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43906
GHSA-GMRP-X952-3M66
USN-8438-1

Affected Products

Linuxmint
Openimageio
Ubuntu