#1139915 openimageio: CVE-2026-43903 CVE-2026-43904 CVE-2026-43905 CVE-2026-43906 CVE-2026-43907 CVE-2026-43908 CVE-2026-43909 CVE-2026-43996

Package:
src:openimageio
Source:
src:openimageio
Submitter:
Salvatore Bonaccorso
Date:
2026-10-07 00:03:05 UTC
Severity:
normal
Tags:
#1139915#5
Date:
2026-06-13 11:33:46 UTC
From:
To:
Hi,

The following vulnerabilities were published for openimageio.

This is  a substantial batch of CVEs, please help to properly assess
them.

CVE-2026-43903[0]:
| OpenImageIO is a toolset for reading, writing, and manipulating
| image files of any image file format relevant to VFX / animation.
| Prior to 3.0.18.0 and 3.1.13.0, sgiinput.cpp:265,274 use
| OIIO_DASSERT for bounds checking in the RLE decode loop. In release
| builds, OIIO_DASSERT compiles to ((void)sizeof(x)) (dassert.h:210),
| making all bounds checks no-ops. A crafted .sgi file with RLE count
| exceeding scanline width causes heap buffer overflow and crash. This
| vulnerability is fixed in 3.0.18.0 and 3.1.13.0.


CVE-2026-43904[1]:
| OpenImageIO is a toolset for reading, writing, and manipulating
| image files of any image file format relevant to VFX / animation.
| Prior to 3.0.18.0 and 3.1.13.0, softimageinput.cpp:469 (mixed RLE)
| and :345 (pure RLE) do not clamp the run length to remaining
| scanline width before writing pixels. The raw packet path (line 403)
| correctly clamps with std::min, but RLE paths skip this check. A
| crafted .pic file causes heap overflow up to 65535 bytes. This
| vulnerability is fixed in 3.0.18.0 and 3.1.13.0.


CVE-2026-43905[2]:
| OpenImageIO is a toolset for reading, writing, and manipulating
| image files of any image file format relevant to VFX / animation.
| Prior to 3.0.18.0 and 3.1.13.0, jpeg2000input.cpp:395 computes
| buffer size as const int bufsize = w * h * ch * buffer_bpp using
| signed 32-bit arithmetic. When the product exceeds INT_MAX, the
| result wraps to 0 or a small value. m_buf.resize() allocates an
| undersized buffer, and subsequent pixel write loops cause heap
| overflow. Conditional on USE_OPENJPH build flag. This vulnerability
| is fixed in 3.0.18.0 and 3.1.13.0.


CVE-2026-43906[3]:
| OpenImageIO is a toolset for reading, writing, and manipulating
| image files of any image file format relevant to VFX / animation.
| Prior to 3.0.18.0 and 3.1.13.0, a heap-based buffer overflow in the
| HEIF decoder of OpenImageIO allows out-of-bounds writes via crafted
| images due to a subimage metadata mismatch, leading to memory
| corruption and potential code execution. This vulnerability is fixed
| in 3.0.18.0 and 3.1.13.0.


CVE-2026-43907[4]:
| OpenImageIO is a toolset for reading, writing, and manipulating
| image files of any image file format relevant to VFX / animation.
| Prior to 3.0.18.0 and 3.1.13.0, a signed integer overflow in
| QueryRGBBufferSizeInternal() in DPXColorConverter.cpp leads to a
| heap-based out-of-bounds write when processing crafted DPX image
| files. The function computes buffer sizes using 32-bit signed
| integer arithmetic with negative multipliers (e.g., pixels * -3 *
| bytes for kCbYCr descriptors and pixels * -4 * bytes for kABGR
| descriptors), where a negative result is used as an in-band signal
| that no separate buffer is needed. When the pixel count is
| sufficiently large, the multiplication overflows INT_MIN and wraps
| to a small positive value. The caller in dpxinput.cpp interprets
| this positive value as a required buffer size, allocates an
| undersized heap buffer via m_decodebuf.resize(), and then writes the
| full image data into it via fread, resulting in a heap buffer
| overflow. An attacker can exploit this by crafting a DPX file that
| triggers the overflow, causing a denial of service (crash) or
| potentially arbitrary code execution through heap corruption in any
| application that reads pixel data using OpenImageIO. This
| vulnerability is fixed in 3.0.18.0 and 3.1.13.0.


CVE-2026-43908[5]:
| OpenImageIO is a toolset for reading, writing, and manipulating
| image files of any image file format relevant to VFX / animation.
| Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in
| the pixel-loop index expression i * 3 inside ConvertCbYCrYToRGB()
| causes the function to compute a large negative pointer offset into
| the output buffer, producing an out-of-bounds write that crashes the
| process. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0.


CVE-2026-43909[6]:
| OpenImageIO is a toolset for reading, writing, and manipulating
| image files of any image file format relevant to VFX / animation.
| Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in
| the loop index expression i * 4 inside SwapRGBABytes() causes the
| function to compute a large negative pointer offset when processing
| kABGR DPX images with large dimensions. The immediate crash is an
| out-of-bounds read (the memcpy at line 45 reads from &input[i * 4]
| first), but the subsequent write operations at lines 46–49 target
| the same wrapped offset — making this a combined OOB read+write
| primitive. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0.


CVE-2026-43996[7]:
| OpenImageIO is a toolset for reading, writing, and manipulating
| image files of any image file format relevant to VFX / animation.
| Prior to 3.0.18.0 and 3.1.13.0, the bounds check in
| TGAInput::decode_pixel computes k + palbytespp as unsigned 32-bit
| arithmetic. When k = 0xFFFFFFFC and palbytespp = 4, the addition
| wraps to 0, which compares less than palette_alloc_size and passes
| the check. The subsequent palette access uses the unwrapped k
| (0xFFFFFFFC) as the index, reading ~4 GB past the start of the
| palette buffer — SEGV. This vulnerability is fixed in 3.0.18.0 and
| 3.1.13.0.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-43903
https://www.cve.org/CVERecord?id=CVE-2026-43903
[1] https://security-tracker.debian.org/tracker/CVE-2026-43904
https://www.cve.org/CVERecord?id=CVE-2026-43904
[2] https://security-tracker.debian.org/tracker/CVE-2026-43905
https://www.cve.org/CVERecord?id=CVE-2026-43905
[3] https://security-tracker.debian.org/tracker/CVE-2026-43906
https://www.cve.org/CVERecord?id=CVE-2026-43906
[4] https://security-tracker.debian.org/tracker/CVE-2026-43907
https://www.cve.org/CVERecord?id=CVE-2026-43907
[5] https://security-tracker.debian.org/tracker/CVE-2026-43908
https://www.cve.org/CVERecord?id=CVE-2026-43908
[6] https://security-tracker.debian.org/tracker/CVE-2026-43909
https://www.cve.org/CVERecord?id=CVE-2026-43909
[7] https://security-tracker.debian.org/tracker/CVE-2026-43996
https://www.cve.org/CVERecord?id=CVE-2026-43996

Regards,
Salvatore

#1139915#10
Date:
2026-10-07 00:00:17 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
openimageio, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139915@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sébastien Noel <twolife@debian.org> (supplier of updated openimageio package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 05 Oct 2026 09:19:17 +0200
Source: openimageio
Binary: libopenimageio-dev libopenimageio-doc libopenimageio3.1 libopenimageio3.1-dbgsym openimageio-tools openimageio-tools-dbgsym python3-openimageio python3-openimageio-dbgsym
Architecture: source amd64 all
Version: 3.1.18.0+dfsg-1
Distribution: experimental
Urgency: medium
Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
Changed-By: Sébastien Noel <twolife@debian.org>
Description:
 libopenimageio-dev - Library for reading and writing images - development
 libopenimageio-doc - Library for reading and writing images - documentation
 libopenimageio3.1 - Library for reading and writing images - runtime
 openimageio-tools - Library for reading and writing images - command line tools
 python3-openimageio - Library for reading and writing images - Python bindings
Closes: 1094410 1094411 1135382 1139915 1148554
Changes:
 openimageio (3.1.18.0+dfsg-1) experimental; urgency=medium
 .
   * Team upload.
 .
   [ Sébastien Noel ]
   * New upstream release, addressing the following security issues:
     - CVE-2024-55193: NULL pointer dereference (Closes: #1094411)
     - CVE-2024-55194: Heap overflow (Closes: #1094410)
     - CVE-2026-7582: Out-of-bounds write (Closes: #1135382)
     - CVE-2026-43903, CVE-2026-43904, CVE-2026-43905, CVE-2026-43906,
       CVE-2026-43907, CVE-2026-43908, CVE-2026-43909, CVE-2026-43996
       (Closes: #1139915)
     - CVE-2026-65969, CVE-2026-63638, CVE-2026-63635, CVE-2026-63422,
       CVE-2026-63420, CVE-2026-63419, CVE-2026-59956, CVE-2026-59181,
       CVE-2026-59156 (Closes: #1148554)
   * Update package name to match soname bump:
     - libopenimageio2.5 → libopenimageio3.1
   * Switch Build-Depends from Qt5 to Qt6
   * Add Build-Depends on libjxl-dev
   * Cleanup d/copyright
 .
   [ Antoine Lassagne ]
   * Enable python autopkgtests
Checksums-Sha1:
 3a39df62f5068cf5a24685d7b78f900943484720 2539 openimageio_3.1.18.0+dfsg-1.dsc
 9f36a9eafbd0f0ce8c1feca37b201a6bf0280ce9 47428552 openimageio_3.1.18.0+dfsg.orig.tar.xz
 2c6e9ed2003d8dcab99f8c436b9b5f5e84a633f7 18716 openimageio_3.1.18.0+dfsg-1.debian.tar.xz
 70e30d3498cf6d70c2ecf844dcc76371545a88b9 498452 libopenimageio-dev_3.1.18.0+dfsg-1_amd64.deb
 f280a0131791431f172b81321d0194588c0c10a0 302448 libopenimageio-doc_3.1.18.0+dfsg-1_all.deb
 7e9dd5223a83ae369e224177be6667ee9ebd0940 56471300 libopenimageio3.1-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 088d6eb9017c20504f8f6fb310720c7580919c38 2780320 libopenimageio3.1_3.1.18.0+dfsg-1_amd64.deb
 da464b2547f988fe5a5287f249da6b92aab4bf65 14986400 openimageio-tools-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 f89861f49d9406cbbabb4d21bc30aa88c4441ab2 799152 openimageio-tools_3.1.18.0+dfsg-1_amd64.deb
 07933c2dc353d7443de151ab8ebf363c8ab7dc80 25123 openimageio_3.1.18.0+dfsg-1_amd64.buildinfo
 09e92c6264d0202c6d3af8804c5ff16fbbe79cbb 12184364 python3-openimageio-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 639f243ae49e87dbfe399a57fc5711491f645006 689764 python3-openimageio_3.1.18.0+dfsg-1_amd64.deb
Checksums-Sha256:
 981c04885a900eca955afccea2a85abaa7f0aeb4b3559ecdfc3cea232d35a94c 2539 openimageio_3.1.18.0+dfsg-1.dsc
 394817371fda03656b61ef4e7e160b687023106023092f1deba3c891292029ae 47428552 openimageio_3.1.18.0+dfsg.orig.tar.xz
 a8ec541a50a3762034d515da0ec75c478fa28299974db5377f33c1e883294a73 18716 openimageio_3.1.18.0+dfsg-1.debian.tar.xz
 70cba4693df565b44e867623ef17dea358cc28c8f83182cccc2bb11e5928c69c 498452 libopenimageio-dev_3.1.18.0+dfsg-1_amd64.deb
 c4d7c401b54e0fd04cc840652e3b0719310800a1293576bbcdd334de8ab1aa0f 302448 libopenimageio-doc_3.1.18.0+dfsg-1_all.deb
 19cc5b68c11cb96372eae388b26726ec119d1aa2b9e7dfcdd6230f97eb02c5f3 56471300 libopenimageio3.1-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 fe51387d47f37504ea4bd7f133b6fa5d5d9a737214f6437572f9194419c60315 2780320 libopenimageio3.1_3.1.18.0+dfsg-1_amd64.deb
 7937f83c9ebda48d6a7e62822f045762c23f5d05aad3cba307f1e70f02ddb86b 14986400 openimageio-tools-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 9c72be594758073947190700250d45fe000b7b059a39785a0edcf946a1fd3307 799152 openimageio-tools_3.1.18.0+dfsg-1_amd64.deb
 8d9da87c24c156669fb901d0a9d965c78a9d5c424c8e315a4a951bd755024f15 25123 openimageio_3.1.18.0+dfsg-1_amd64.buildinfo
 f2633c528511fa957c23b33639bbe20012f07964bfebe134bccf8713cb261831 12184364 python3-openimageio-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 6a694e91e1534f040c314708591ad9a94d06f3dff5a937d225e4310b1cead4f9 689764 python3-openimageio_3.1.18.0+dfsg-1_amd64.deb
Files:
 0bb58277913c65a43ff800155c1ed553 2539 libs optional openimageio_3.1.18.0+dfsg-1.dsc
 138f185e31e22c5acafbb3d170416493 47428552 libs optional openimageio_3.1.18.0+dfsg.orig.tar.xz
 22e1292ff18d1054cdc68c95d5536f0e 18716 libs optional openimageio_3.1.18.0+dfsg-1.debian.tar.xz
 4419728263f26550db15561b021603d1 498452 libdevel optional libopenimageio-dev_3.1.18.0+dfsg-1_amd64.deb
 88b14a8cadc5d86cfc5a2879556a837c 302448 doc optional libopenimageio-doc_3.1.18.0+dfsg-1_all.deb
 1bebd7e5e629d01f4fe437930b26f0b6 56471300 debug optional libopenimageio3.1-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 57bfd260b292a4764284abd632697920 2780320 libs optional libopenimageio3.1_3.1.18.0+dfsg-1_amd64.deb
 78fc885c2becac920558bc4128d5d9eb 14986400 debug optional openimageio-tools-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 3bf46f6b75d5949ac42722975efc4000 799152 graphics optional openimageio-tools_3.1.18.0+dfsg-1_amd64.deb
 15704099cfe99bf6f0867bfaa5845a31 25123 libs optional openimageio_3.1.18.0+dfsg-1_amd64.buildinfo
 ba5a47416e7740d5da06c2ef9dc1b801 12184364 debug optional python3-openimageio-dbgsym_3.1.18.0+dfsg-1_amd64.deb
 c53125cfc98c4437831d6594cd33dec8 689764 python optional python3-openimageio_3.1.18.0+dfsg-1_amd64.deb
-----BEGIN PGP SIGNATURE-----

iQFHBAEBCgAxFiEEdlP6my3wO8aMe9FCrKAIuMk0p9QFAmrDVAQTHHR3b2xpZmVA
ZGViaWFuLm9yZwAKCRCsoAi4yTSn1E7FB/9uBj2LILpzhvatJIHCd3EoiSeVZqH2
5uk/diElZclNOk/LEIVFftFSycaWIYQ/mj2+0qMSGLrsTNFBSXULdKZoDQisiaUf
Vt/w+QueoBwdGYcDGFnkk6wA6DDWme+Fb2ZzFYmrZoQBuEpgytPWQc0ohiklHh4N
B0iRD/kwpJw5e1tvNTjCNOle0KuQ63+jk7gusIEtJZAvppsz/ubElCT8RcmWPG6o
gfTq++ESjIVx2UIwKPJlN7k6WrLFw8/JLNxLn8QQGVwcBH1W1Bac1OXMP8A9RhaX
vuR97bvVDCVvrURtd+x0ReYMfQwdPWM+h8EHNjgKOAhqYZ+w2kzlO1sR
=I41R
-----END PGP SIGNATURE-----