Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 16 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openimageio
Openimageio openimageio |
|
| CPEs | cpe:2.3:a:openimageio:openimageio:*:*:*:*:*:*:*:* cpe:2.3:a:openimageio:openimageio:3.2.0.0:dev:*:*:*:*:*:* cpe:2.3:a:openimageio:openimageio:3.2.0.2:dev:*:*:*:*:*:* |
|
| Vendors & Products |
Openimageio
Openimageio openimageio |
Fri, 15 May 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Academysoftwarefoundation
Academysoftwarefoundation openimageio |
|
| Vendors & Products |
Academysoftwarefoundation
Academysoftwarefoundation openimageio |
Thu, 14 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, the bounds check in TGAInput::decode_pixel computes k + palbytespp as unsigned 32-bit arithmetic. When k = 0xFFFFFFFC and palbytespp = 4, the addition wraps to 0, which compares less than palette_alloc_size and passes the check. The subsequent palette access uses the unwrapped k (0xFFFFFFFC) as the index, reading ~4 GB past the start of the palette buffer — SEGV. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0. | |
| Title | OpenImageIO: Integer wraparound in bounds check of decode_pixel leads to out-of-bounds read in TGA paletted image decoder | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-16T00:53:37.525Z
Reserved: 2026-05-04T20:24:31.917Z
Link: CVE-2026-43996
Updated: 2026-05-16T00:53:29.241Z
Status : Modified
Published: 2026-05-14T20:17:07.300
Modified: 2026-05-16T01:16:16.570
Link: CVE-2026-43996
No data.
OpenCVE Enrichment
Updated: 2026-05-15T11:15:25Z