Upstream information

CVE-2026-63635 at MITRE

Description

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal validation when oiio:rawcolor or psd:rawdata is enabled. psdinput::setup() then uses the attacker-controlled value to index fixed color-mode tables, causing a global out-of-bounds read and potentially a bogus allocation, resulting in denial of service. The affected implementation is identified by src/psd.imageio/psdinput.cpp, PSDInput::validate_header(), PSDInput::setup(), oiio:RawColor, psd:RawData, color_mode, and mode_channel_count, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.

SUSE information

Overall state of this security issue: New

This issue is currently rated as having moderate severity.

CVSS v3 Scores
CVSS detail CNA (GitHub)
Base Score 5.5
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • OpenImageIO >= 3.1.16.0-1.1
  • OpenImageIO-devel >= 3.1.16.0-1.1
  • libOpenImageIO3_1 >= 3.1.16.0-1.1
  • libOpenImageIO_Util3_1 >= 3.1.16.0-1.1
  • python3-OpenImageIO >= 3.1.16.0-1.1
Patchnames:
openSUSE-Tumbleweed-2026-11442


SUSE Timeline for this CVE

CVE page created: Wed Aug 5 11:41:07 2026
CVE page last modified: Fri Sep 18 23:01:58 2026