Out-of-bounds read in oiio - CVE-2026-63420
Published: August 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in `interleave_row` when parsing a crafted indexed PSD file with transparency metadata in raw PSD color output mode. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
User interaction is required to open the crafted PSD file, and exploitation requires `oiio:RawColor=1` or `psd:RawData=1`.