Out-of-bounds read in oiio - CVE-2026-63635
Published: August 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in PSDInput::setup() when parsing a crafted PSD file through the RawColor input path. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
Only applications that enable raw PSD color output with oiio:RawColor=1 or psd:RawData=1 are vulnerable.