#1094410 openimageio: CVE-2024-55194

Package:
src:openimageio
Source:
src:openimageio
Submitter:
Salvatore Bonaccorso
Date:
2026-10-07 00:03:02 UTC
Severity:
normal
Tags:
#1094410#5
Date:
2025-01-27 21:17:52 UTC
From:
To:
Hi,

The following vulnerability was published for openimageio.

CVE-2024-55194[0]:
| OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow
| via the component /OpenImageIO/fmath.h.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-55194
https://www.cve.org/CVERecord?id=CVE-2024-55194
[1] https://github.com/AcademySoftwareFoundation/OpenImageIO/issues/4552
[2] https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/34b29f33217e58b7f0d42c059ecf1696c381322a

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1094410#12
Date:
2025-02-16 17:49:35 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
openimageio, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1094410@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Matteo F. Vescovi <mfv@debian.org> (supplier of updated openimageio package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 16 Feb 2025 17:33:32 +0100
Source: openimageio
Architecture: source
Version: 2.5.18.0+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
Changed-By: Matteo F. Vescovi <mfv@debian.org>
Closes: 1094398 1094408 1094410 1094411
Changes:
 openimageio (2.5.18.0+dfsg-1) unstable; urgency=medium
 .
   * New upstream release
     (Closes: #1094398, #1094408, #1094410, #1094411)
     This release addresses the following security issues:
     CVE-2024-55192, CVE-2024-55193, CVE-2024-55194, CVE-2024-55195
Checksums-Sha1:
 4f87c9ddc362a31c8efb35e3e2a58b5ede8464ed 3008 openimageio_2.5.18.0+dfsg-1.dsc
 cfedca9871ef8a715cb38589daec000c11d5b81a 44959560 openimageio_2.5.18.0+dfsg.orig.tar.xz
 c8949b7efc15784d4a8170f1163aed5091e6cb62 17728 openimageio_2.5.18.0+dfsg-1.debian.tar.xz
 e5e1750476f3b004c0e69536f70c6c1dee1eddbd 8005 openimageio_2.5.18.0+dfsg-1_source.buildinfo
Checksums-Sha256:
 3674d51e73a1755909f336d6ae332a6b6b602b06ce1a7bb36f22d1804579800d 3008 openimageio_2.5.18.0+dfsg-1.dsc
 0dc2185aac5e01a2e5a1a804f558c1190ea048650a7fedef1033a1616abcac80 44959560 openimageio_2.5.18.0+dfsg.orig.tar.xz
 c50d8d4a12849ab6d8c2796668dd661c4f909dd4c482b8a69ba9a88bc35f1ae2 17728 openimageio_2.5.18.0+dfsg-1.debian.tar.xz
 f69b48766b8d869214e928205b1f07e6d4256eec644ece7c7d8757f2397272aa 8005 openimageio_2.5.18.0+dfsg-1_source.buildinfo
Files:
 a24fac3647444a68bf29bff5e1ef57f2 3008 libs optional openimageio_2.5.18.0+dfsg-1.dsc
 1caa3b383b35c51942abd3a70e97188c 44959560 libs optional openimageio_2.5.18.0+dfsg.orig.tar.xz
 8c1f9cdc8b33068b7ba919842948a5a6 17728 libs optional openimageio_2.5.18.0+dfsg-1.debian.tar.xz
 fb1d2091ba614a0162b8e064ca9ed6c1 8005 libs optional openimageio_2.5.18.0+dfsg-1_source.buildinfo
iQKTBAEBCgB9FiEE890J+NqH0d9QRsmbBhL0lE7NzVoFAmeyGJBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEYz
REQwOUY4REE4N0QxREY1MDQ2Qzk5QjA2MTJGNDk0NEVDRENENUEACgkQBhL0lE7N
zVoxXxAArrDC+75jlfKYmTs5lpG/S4dcoFKf/2V55QpN121GbC4ELqULQubK434L
DC2odUx/WF/lPoChLR//tGnpLfFrkCJoWS0PZZTBB6SCLq7veG90o0PkqGd2lVnD
Vr3r3iEpe0yrMfGOge+ZF0WZYWzmCphf0na0G5BEDWnki6hLEfdoupk7j0BXAKGs
MktJzcNX89/8LB0qsrlVLvNEMObtbnAjUTvzbzvvIJi8sqRUfF+MMEPfEEwayYqh
+RXlMmUZzeoBEvYaljGd6H/K73lxSdBx8Qr4bOPbWzR/sUHHM4gFUyxwqmRtvv1c
oIMhf+JDLcbN2yPh1FuTeVe+nmfW8ngR5mmkL37plXHaQ8I3GoaER66yGP1Cxv7P
Q09Ee6XTonQiSKMlJnMhcaZOLrtswDt8pQ1y+DJLR16QnuI2u5VDhMux4yPwfufM
0wnOhf3XtxriyUKZErPmhmv5VuvVVNArSc0720aljwvUMHxe+RQztjHYT/It1nCq
ZVNc++zDeSe6KCaPuCFpHfZnpP+s/jgfrilIp75bNYPRVZw9YTAjp+df050x5XS/
5kz3i5xgZlxmugGYdsFrdhYdq6IMPpablErmZcemn8ibsSNqIBoRWUA8QfcSJaPG
/JNChIhDidXXHOKGUS0b23A2wRAmHWk51+IOT+PNjpI7g0d1MAs=
=Il0q
-----END PGP SIGNATURE-----

#1094410#17
Date:
2025-02-17 18:36:55 UTC
From:
To:
Hi Matteo

CVE-2024-55194 neither looks fixed with 2.5.18.0, can you clarify?

Regards,
Salvtore

#1094410#26
Date:
2026-10-06 23:31:32 UTC
From:
To:
The Debian NEW review of openimageio 3.1.18.0+dfsg-1 has been completed.

Decision: ACCEPTED
Reviewer: Andrew McMillan

Review comment:

Hi,

Some issues, all in the Files: src/* … License: Apache-2.0 catch-all:

1. FarmHash is MIT, not Apache-only. src/libutil/farmhash.cpp:1-21 and src/include/OpenImageIO/detail/farmhash.h:1-16 both open with the full MIT text, Copyright (c) 2014 Google, Inc. (OIIO's additions on top are Apache-2.0). Neither file has a dedicated stanza; both fall into the Apache-2.0 catch-all, so the holder "Google" and the MIT licence are absent. Note upstream's own THIRD-PARTY.md (lines 132-133) documents "FarmHash, … (c) Copyright 2014 Google, Inc., MIT license."

Fix: add a Files: stanza for these two (and src/include/OpenImageIO/hash.h, below) with Copyright: 2014, Google, Inc. and License: Expat/Apache-2.0 and Expat.


2. src/include/OpenImageIO/hash.h embeds fasthash under full MIT. At lines 33-63 a delimited namespace fasthash carries the complete MIT licence, Copyright (C) 2012 Zilong Tan (eric.zltan@gmail.com). The file's own header is Apache-2.0 (its farmhash/xxhash namespaces are fine under the catch-all: farmhash is Google MIT but hash.h only declares it; xxhash is BSD-2). Zilong Tan and the MIT portion are not recorded.

Fix: same stanza as (1), or note the embedded MIT portion in the hash.h coverage.


3. src/libutil/strutil.cpp embeds an MIT UTF-8 decoder and a Zlib base64 encoder. Lines 1585-1611: Bjoern Hoehrmann's UTF-8 decoder, Copyright (c) 2008-2009 Bjoern Hoehrmann, // SPDX-License-Identifier: MIT; lines 1664-1689: René Nyffenegger's base64, Zlib licence. Neither licence/holder appears for this file (it is swept wholesale into Apache-2.0).

Fix: add the file to a stanza listing License: Apache-2.0 and Expat and Zlib with the two holders, or mark the embedded portions.


4. src/libutil/SHA1.cpp is public domain, not Apache. Header (lines 1-5): "100% free public domain implementation of the SHA-1 algorithm by Dominik Reichl". No dedicated stanza — swept into the Apache catch-all.

Fix: add Files: src/libutil/SHA1.cpp with Copyright: no copyright is claimed / License: public-domain (mirror the existing hashes.cpp/stb_sprintf.h entry).


5. src/cmake/modules/FindLibRaw.cmake is a third-party BSD-3 file, mislabelled Apache. Header (lines 10-15): Copyright (c) 2013, Pino Toscano, Copyright (c) 2013, Gilles Caulier, "Redistribution and use is allowed according to the terms of the BSD license" (it is the CMake/KDE FindLibRaw, cf. its COPING-CMAKE-SCRIPTS reference). It has no stanza and is assigned Apache-2.0 by the catch-all.

Fix: add a stanza with Copyright: 2013, Pino Toscano / Gilles Caulier and License: BSD-3-clause.


6. src/include/OpenImageIO/function_view.h contains LLVM-derived code under the University of Illinois/NCSA licence. Lines 8-33 reproduce that BSD-3-style licence, Copyright (c) 2003-2018 University of Illinois at Urbana-Champaign. The file is only covered as Apache-2.0.

Fix: add the file to a stanza noting Apache-2.0 for the OIIO part plus the UIUC/BSD-3 portion (THIRD-PARTY.md documents this too).


7. Minor: README.md is CC-BY-4.0, not Apache. Top-level README.md:1 carries SPDX-License-Identifier: CC-BY-4.0, but the Apache stanza assigns it License: Apache-2.0 (the file is also shipped by libopenimageio-doc.docs). Both are free; this is only an accuracy nit. THIRD-PARTY.md/AGENTS.md have no SPDX header and Apache assignment is reasonable.



Thanks!

Full review details: https://dfsg-new-queue.debian.org/reviews/openimageio

#1094410#31
Date:
2026-10-07 00:00:17 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
openimageio, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1094410@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sébastien Noel <twolife@debian.org> (supplier of updated openimageio package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 05 Oct 2026 09:19:17 +0200
Source: openimageio
Binary: libopenimageio-dev libopenimageio-doc libopenimageio3.1 libopenimageio3.1-dbgsym openimageio-tools openimageio-tools-dbgsym python3-openimageio python3-openimageio-dbgsym
Architecture: source amd64 all
Version: 3.1.18.0+dfsg-1
Distribution: experimental
Urgency: medium
Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
Changed-By: Sébastien Noel <twolife@debian.org>
Description:
 libopenimageio-dev - Library for reading and writing images - development
 libopenimageio-doc - Library for reading and writing images - documentation
 libopenimageio3.1 - Library for reading and writing images - runtime
 openimageio-tools - Library for reading and writing images - command line tools
 python3-openimageio - Library for reading and writing images - Python bindings
Closes: 1094410 1094411 1135382 1139915 1148554
Changes:
 openimageio (3.1.18.0+dfsg-1) experimental; urgency=medium
 .
   * Team upload.
 .
   [ Sébastien Noel ]
   * New upstream release, addressing the following security issues:
     - CVE-2024-55193: NULL pointer dereference (Closes: #1094411)
     - CVE-2024-55194: Heap overflow (Closes: #1094410)
     - CVE-2026-7582: Out-of-bounds write (Closes: #1135382)
     - CVE-2026-43903, CVE-2026-43904, CVE-2026-43905, CVE-2026-43906,
       CVE-2026-43907, CVE-2026-43908, CVE-2026-43909, CVE-2026-43996
       (Closes: #1139915)
     - CVE-2026-65969, CVE-2026-63638, CVE-2026-63635, CVE-2026-63422,
       CVE-2026-63420, CVE-2026-63419, CVE-2026-59956, CVE-2026-59181,
       CVE-2026-59156 (Closes: #1148554)
   * Update package name to match soname bump:
     - libopenimageio2.5 → libopenimageio3.1
   * Switch Build-Depends from Qt5 to Qt6
   * Add Build-Depends on libjxl-dev
   * Cleanup d/copyright
 .
   [ Antoine Lassagne ]
   * Enable python autopkgtests
Checksums-Sha1:
 3a39df62f5068cf5a24685d7b78f900943484720 2539 openimageio_3.1.18.0+dfsg-1.dsc
 9f36a9eafbd0f0ce8c1feca37b201a6bf0280ce9 47428552 openimageio_3.1.18.0+dfsg.orig.tar.xz
 2c6e9ed2003d8dcab99f8c436b9b5f5e84a633f7 18716 openimageio_3.1.18.0+dfsg-1.debian.tar.xz
 70e30d3498cf6d70c2ecf844dcc76371545a88b9 498452 libopenimageio-dev_3.1.18.0+dfsg-1_amd64.deb
 f280a0131791431f172b81321d0194588c0c10a0 302448 libopenimageio-doc_3.1.18.0+dfsg-1_all.deb
 7e9dd5223a83ae369e224177be6667ee9ebd0940 56471300 libopenimageio3.1-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 088d6eb9017c20504f8f6fb310720c7580919c38 2780320 libopenimageio3.1_3.1.18.0+dfsg-1_amd64.deb
 da464b2547f988fe5a5287f249da6b92aab4bf65 14986400 openimageio-tools-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 f89861f49d9406cbbabb4d21bc30aa88c4441ab2 799152 openimageio-tools_3.1.18.0+dfsg-1_amd64.deb
 07933c2dc353d7443de151ab8ebf363c8ab7dc80 25123 openimageio_3.1.18.0+dfsg-1_amd64.buildinfo
 09e92c6264d0202c6d3af8804c5ff16fbbe79cbb 12184364 python3-openimageio-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 639f243ae49e87dbfe399a57fc5711491f645006 689764 python3-openimageio_3.1.18.0+dfsg-1_amd64.deb
Checksums-Sha256:
 981c04885a900eca955afccea2a85abaa7f0aeb4b3559ecdfc3cea232d35a94c 2539 openimageio_3.1.18.0+dfsg-1.dsc
 394817371fda03656b61ef4e7e160b687023106023092f1deba3c891292029ae 47428552 openimageio_3.1.18.0+dfsg.orig.tar.xz
 a8ec541a50a3762034d515da0ec75c478fa28299974db5377f33c1e883294a73 18716 openimageio_3.1.18.0+dfsg-1.debian.tar.xz
 70cba4693df565b44e867623ef17dea358cc28c8f83182cccc2bb11e5928c69c 498452 libopenimageio-dev_3.1.18.0+dfsg-1_amd64.deb
 c4d7c401b54e0fd04cc840652e3b0719310800a1293576bbcdd334de8ab1aa0f 302448 libopenimageio-doc_3.1.18.0+dfsg-1_all.deb
 19cc5b68c11cb96372eae388b26726ec119d1aa2b9e7dfcdd6230f97eb02c5f3 56471300 libopenimageio3.1-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 fe51387d47f37504ea4bd7f133b6fa5d5d9a737214f6437572f9194419c60315 2780320 libopenimageio3.1_3.1.18.0+dfsg-1_amd64.deb
 7937f83c9ebda48d6a7e62822f045762c23f5d05aad3cba307f1e70f02ddb86b 14986400 openimageio-tools-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 9c72be594758073947190700250d45fe000b7b059a39785a0edcf946a1fd3307 799152 openimageio-tools_3.1.18.0+dfsg-1_amd64.deb
 8d9da87c24c156669fb901d0a9d965c78a9d5c424c8e315a4a951bd755024f15 25123 openimageio_3.1.18.0+dfsg-1_amd64.buildinfo
 f2633c528511fa957c23b33639bbe20012f07964bfebe134bccf8713cb261831 12184364 python3-openimageio-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 6a694e91e1534f040c314708591ad9a94d06f3dff5a937d225e4310b1cead4f9 689764 python3-openimageio_3.1.18.0+dfsg-1_amd64.deb
Files:
 0bb58277913c65a43ff800155c1ed553 2539 libs optional openimageio_3.1.18.0+dfsg-1.dsc
 138f185e31e22c5acafbb3d170416493 47428552 libs optional openimageio_3.1.18.0+dfsg.orig.tar.xz
 22e1292ff18d1054cdc68c95d5536f0e 18716 libs optional openimageio_3.1.18.0+dfsg-1.debian.tar.xz
 4419728263f26550db15561b021603d1 498452 libdevel optional libopenimageio-dev_3.1.18.0+dfsg-1_amd64.deb
 88b14a8cadc5d86cfc5a2879556a837c 302448 doc optional libopenimageio-doc_3.1.18.0+dfsg-1_all.deb
 1bebd7e5e629d01f4fe437930b26f0b6 56471300 debug optional libopenimageio3.1-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 57bfd260b292a4764284abd632697920 2780320 libs optional libopenimageio3.1_3.1.18.0+dfsg-1_amd64.deb
 78fc885c2becac920558bc4128d5d9eb 14986400 debug optional openimageio-tools-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 3bf46f6b75d5949ac42722975efc4000 799152 graphics optional openimageio-tools_3.1.18.0+dfsg-1_amd64.deb
 15704099cfe99bf6f0867bfaa5845a31 25123 libs optional openimageio_3.1.18.0+dfsg-1_amd64.buildinfo
 ba5a47416e7740d5da06c2ef9dc1b801 12184364 debug optional python3-openimageio-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 c53125cfc98c4437831d6594cd33dec8 689764 python optional python3-openimageio_3.1.18.0+dfsg-1_amd64.deb
-----BEGIN PGP SIGNATURE-----

iQFHBAEBCgAxFiEEdlP6my3wO8aMe9FCrKAIuMk0p9QFAmrDVAQTHHR3b2xpZmVA
ZGViaWFuLm9yZwAKCRCsoAi4yTSn1E7FB/9uBj2LILpzhvatJIHCd3EoiSeVZqH2
5uk/diElZclNOk/LEIVFftFSycaWIYQ/mj2+0qMSGLrsTNFBSXULdKZoDQisiaUf
Vt/w+QueoBwdGYcDGFnkk6wA6DDWme+Fb2ZzFYmrZoQBuEpgytPWQc0ohiklHh4N
B0iRD/kwpJw5e1tvNTjCNOle0KuQ63+jk7gusIEtJZAvppsz/ubElCT8RcmWPG6o
gfTq++ESjIVx2UIwKPJlN7k6WrLFw8/JLNxLn8QQGVwcBH1W1Bac1OXMP8A9RhaX
vuR97bvVDCVvrURtd+x0ReYMfQwdPWM+h8EHNjgKOAhqYZ+w2kzlO1sR
=I41R
-----END PGP SIGNATURE-----