Integer overflow in Openimageio - CVE-2026-43908
Published: May 5, 2026
Openimageio
AcademySoftwareFoundation
Description
The vulnerability allows a remote attacker to cause a denial of service and potentially execute arbitrary code.
The vulnerability exists due to integer overflow leading to an out-of-bounds write in the ConvertCbYCrYToRGB function in the DPX 4:2:2 decoder when parsing a crafted DPX file. A remote attacker can supply a specially crafted DPX file to cause a denial of service and potentially execute arbitrary code.
User interaction is required to open or process a crafted DPX file.