Out-of-bounds read in oiio - CVE-2026-65969

 

Out-of-bounds read in oiio - CVE-2026-65969

Published: August 2, 2026


Vulnerability identifier: #VU140736
CSH Severity: Medium
CVSS v4 BT: 4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2026-65969
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in the GifSplitPalette function when processing a malformed TGA image during conversion to GIF output. A remote attacker can supply a specially crafted TGA image to cause a denial of service.

User interaction is required to open or process the crafted image, and the vulnerable path is reached only when writing GIF output.


Affected software

oiio

How to mitigate CVE-2026-65969

Install security update from vendor's website.

oiio - addressed in versions 3.0.21.0, 3.1.16.0

External References