Heap-based buffer overflow in oiio - CVE-2026-67549
Published: August 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and corrupt heap memory.
The vulnerability exists due to a heap-based buffer overflow in TIFFInput::bit_convert() when processing a crafted 1-bit CMYK TIFF file during hash computation. A remote attacker can supply a specially crafted TIFF file to cause a denial of service and corrupt heap memory.
User interaction is required to process the crafted TIFF file, such as via iinfo -hash or oiiotool --hash.