CVE-2026-65969: OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV

Published Sep 18, 2026
·
Updated

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is processed during output close. gifsplitpalette() computes numpixels multiplied by the palette partition width in signed 32-bit arithmetic; a large image overflows that intermediate, corrupts subpixelsa, and drives an out-of-bounds read while building the gif palette, resulting in a process crash and denial of service. The affected implementation is identified by src/gif.imageio/gif.h, GifSplitPalette(), numPixels, subPixelsA, GIFOutput, and truncated TGA input, which define the relevant source path, functions, state, and trigger. This issue is fixed in versions 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1.

Affected Software

1 affected component
Openimageio Openimageio>3.0.21.0<=3.1.16.0, >3.1.16.0<=3.2.0.3-beta1, <3.0.21.0, >3.0.21.0<3.1.16.0, >3.1.16.0<3.2.0.3-beta1, <3.1.16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenImageIO to a version that resolves this vulnerability.

    Fixed in 3.0.21.0
  2. Upgrade

    Upgrade OpenImageIO to a version that resolves this vulnerability.

    Fixed in 3.1.16.0
  3. Upgrade

    Upgrade OpenImageIO to a version that resolves this vulnerability.

    Fixed in 3.2.0.3-beta1

Event History

Sep 18, 2026
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which releases contain the fix?

The issue is fixed in OpenImageIO 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1. Releases prior to those versions are affected.

2

What input and processing conditions are needed to trigger the crash?

A truncated TGA input must leave a pending GIF frame that is processed when GIF output is closed. The vulnerable calculation also requires a large image such that numpixels multiplied by the palette partition width overflows signed 32-bit arithmetic.

3

What is the practical impact of successful exploitation?

The overflow corrupts subPixelsA and causes an out-of-bounds read while the GIF palette is built. This results in a process crash and denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203