CVE-2026-7582 Details
Description
A vulnerability was detected in AcademySoftwareFoundation OpenImageIO up to 3.2.0.1-dev. This vulnerability affects unknown code of the file src/dds.imageio/ddsinput.cpp of the component DDS Image Handler. The manipulation results in out-of-bounds write. The attack needs to be approached locally. The exploit is now public and may be used. The patch is identified as 94ec2deec3e3bf2f2e2ff84d008e27425d626fe2. Applying a patch is advised to resolve this issue.
A vulnerability allowing out-of-bounds write has been identified in Academy Software Foundation OpenImageIO versions through 3.2.0.1-dev. The issue resides in the DDS Image Handler component, specifically within the file ddsinput.cpp. This vulnerability requires local exploitation.
Users are advised to update to the patched version of OpenImageIO. The patch has been merged into the main branch and is available in the latest release.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 1, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/AcademySoftwareFoundation/OpenImageIO/ | [email protected] | ProductVendor |
| https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2 | [email protected] | Source CodeVendor |
| https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5131 | [email protected] | Issue TrackingVendor |
| https://github.com/biniamf/pocs/tree/main/oiio_ddsinput-readimg | [email protected] | Exploit |
| https://vuldb.com/submit/803548 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360529 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/360529/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AcademySoftwareFoundation OpenImageIO | <= 3.2.0.1-dev |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | New CVE Received | [email protected] |
Volerion