Upstream information

CVE-2026-65970 at MITRE

Description

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFInput::read_native_scanlines() return through an error path while asynchronous strip-decompression work remains queued. Because task_set is declared before ok and compressed_scratch, those captured objects are destroyed before the task-set destructor waits, allowing worker tasks to use stale stack and heap storage, resulting in a use-after-scope crash and denial of service. The affected implementation is identified by src/tiff.imageio/tiffinput.cpp, TIFFInput::read_native_scanlines(), task_set, ok, compressed_scratch, and uncompress_one_strip(), which define the relevant source path, functions, state, and trigger. This issue is fixed in 3.1.16.0.

SUSE information

Overall state of this security issue: New

This issue is currently rated as having moderate severity.

CVSS v3 Scores
CVSS detail CNA (GitHub)
Base Score 5.3
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • OpenImageIO >= 3.1.16.0-1.1
  • OpenImageIO-devel >= 3.1.16.0-1.1
  • libOpenImageIO3_1 >= 3.1.16.0-1.1
  • libOpenImageIO_Util3_1 >= 3.1.16.0-1.1
  • python3-OpenImageIO >= 3.1.16.0-1.1
Patchnames:
openSUSE-Tumbleweed-2026-11442


SUSE Timeline for this CVE

CVE page created: Wed Aug 5 11:42:10 2026
CVE page last modified: Fri Sep 18 23:03:31 2026