CVE-2026-7582

Source
https://cve.org/CVERecord?id=CVE-2026-7582
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7582.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-7582
Downstream
Related
Published
2026-05-01T13:45:12Z
Modified
2026-08-12T16:09:20Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
AcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write
Details

A vulnerability was detected in AcademySoftwareFoundation OpenImageIO up to 3.2.0.1-dev. This vulnerability affects unknown code of the file src/dds.imageio/ddsinput.cpp of the component DDS Image Handler. The manipulation results in out-of-bounds write. The attack needs to be approached locally. The exploit is now public and may be used. The patch is identified as 94ec2deec3e3bf2f2e2ff84d008e27425d626fe2. Applying a patch is advised to resolve this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7582.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "3.2.0.1-dev"
                },
                {
                    "last_affected": "3.2.0.1-dev"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/academysoftwarefoundation/openimageio

Affected ranges

Type
GIT
Repo
https://github.com/academysoftwarefoundation/openimageio
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Arnold-3.*
Arnold-3.4.72.0
Release-0.*
Release-0.10.0
Release-1.*
Release-1.0.0
Release-1.0.1
Release-1.1.0
Release-1.1.0-beta1
Release-1.1.0-beta2
Release-1.1.0-beta3
Release-1.1.0-beta4
Release-1.1.1
Release-1.3.0-dev
Release-1.3.1-dev
Release-1.3.2-dev
Release-1.3.3-dev
Release-1.3.4-dev
Release-1.3.5
Release-1.3.5-dev
Release-1.3.6-dev
Release-1.4.1dev
Release-1.4.2dev
Release-1.4.3dev
Release-1.4.4dev
Release-1.4.5dev
Release-1.4.6RC1
Release-1.5.0dev
Release-1.5.1dev
Release-1.5.2dev
Release-1.5.3dev
Release-1.5.4dev-pre-SIMD
Release-1.5.5dev
Release-1.5.6dev
Release-1.5.7dev
Release-1.6.1dev
Release-1.6.2dev
Release-1.6.3dev
Release-1.6.4dev
Release-1.6.6beta
Release-1.7.0dev
Release-1.7.1dev
Release-1.7.2dev
Release-1.7.3dev
Release-1.7.4dev
Release-1.7.5beta
Release-1.7.6RC1
Release-1.8.0dev
Release-1.8.1dev
Release-1.8.2dev
Release-1.8.3dev
Release-1.8.4dev
Release-1.9.1dev
Release-1.9.2dev
Release-1.9.3dev
Release-1.9.4dev
Release-2.*
Release-2.0.0-beta1
Release-2.0.1-RC1
Release-2.1.0-dev
Release-2.1.1-dev
Release-2.1.2-dev
Release-2.1.3-dev
Release-2.1.4.0-dev
Release-2.1.5.0-dev
Release-2.1.7-beta
Release-2.1.8.0-RC1
Release-2.2.0.0-dev
Release-2.2.1.0-dev
Release-2.2.1.1-dev
Release-2.2.2.0-dev
Release-2.2.3.0-dev
Release-2.3.0.0-dev
Release-2.3.1.0-dev
Release-2.3.2.0-dev
Release-2.3.3.0-dev
Release-2.3.4.0-dev
arnold-3.*
arnold-3.4.71.0
spi-Arn3.*
spi-Arn3.4.71.0
spi-Arn3.4.72.0
spi-Arn3.4.73.6
spi-Arn3.4.73.7
spi-Arn3.5.0.0
spi-Arn3.5.10.0
spi-Arn3.5.11.0
spi-Arn3.5.12.0
spi-Arn3.5.13.1
spi-Arn3.5.14.0
spi-Arn3.5.16.0
spi-Arn3.5.2.0
spi-Arn3.5.24.0
spi-Arn3.5.25.0
spi-Arn3.5.26.0
spi-Arn3.5.28.0
spi-Arn3.5.31.0
spi-Arn3.5.35.0
spi-Arn3.5.37.0
spi-Arn3.5.41.0
spi-Arn3.5.45.0
spi-Arn3.5.45.1
spi-Arn3.5.48.0
spi-Arn3.5.5.0
spi-Arn3.5.50.0
spi-Arn3.5.66.0
spi-Arn3.5.68.0
spi-Arn3.5.75.0
spi-Arn3.5.8.0
spi-Arn3.5.82.0
spi-Arn3.5.90.0
spi-Arn3.5.91.0
spi-Arn3.5.93.10
spi-Arn3.6.18.0
spi-Arn3.6.21.3
spi-Arn3.6.27.0
spi-Arn3.6.33.4
spi-Arn3.6.36.0
spi-Arn3.6.64.6
spi-Arn3.6.69.3
spi-Arn3.6.7.1
spi-Arn3.6.72.1
spi-Arn3.7.23.3
spi-Arn3.7.25.0
spi-Arn3.7.42.0
Other
spi-SpComp2-v20
spi-SpComp2-v9
spi-spcomp2-release-38.*
spi-spcomp2-release-38.0
spi-spcomp2-release-39.*
spi-spcomp2-release-39.1
spi-spcomp2-release-41.*
spi-spcomp2-release-41.0
spi-spcomp2-release-42.*
spi-spcomp2-release-42.0-rhel7
spi-spcomp2-release-43.*
spi-spcomp2-release-43.0
spi-spcomp2-release-44.*
spi-spcomp2-release-44.0
spi-spcomp2-release-44.1
spi-spcomp2-release-44.2
spi-spcomp2-release-45.*
spi-spcomp2-release-45.0
spi-spcomp2-release-45.1
spi-spcomp2-release-45.3
spi-spcomp2-release-45.4
spi-spcomp2-release-47.*
spi-spcomp2-release-47.0
spi-spcomp2-release-48.*
spi-spcomp2-release-48.0
spi-spcomp2-release-49.*
spi-spcomp2-release-49.1
spi-v7-Arn3.*
spi-v7-Arn3.4.73.3
spi-v8-Arn3.*
spi-v8-Arn3.4.73.6
spiArn-3.*
spiArn-3.6.74.0
spiArn-3.6.84.0
spiArn-3.6.86.0
spiArn-3.6.94.0
spiArn3.*
spiArn3.5.45.0
spiArn3.5.45.1
spiArn3.5.48.0
spiArn3.5.50.0
spiArn3.5.66.0
spiArn3.5.68.0
spiArn3.5.75.0
spiArn3.5.82.0
v2.*
v2.3.5.0-dev
v2.3.6.0-dev
v2.4.0.0-dev
v2.4.0.1-dev
v2.4.0.2-dev
v2.4.0.3-dev
v2.4.1.1-dev
v2.4.2.0-dev
v2.4.2.1-dev
v2.4.2.2-dev
v2.5.0.0-dev
v2.5.2.0-dev
v2.6.1.0-dev
v2.6.2.0-dev
v2.6.5.0-dev
v3.*
v3.0.0.0-beta1
v3.2.0.0-dev

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7582.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "66395319454866042808915177437853356146",
            "length": 201
        },
        "id": "CVE-2026-7582-1baa23f3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/academysoftwarefoundation/openimageio/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2",
        "target": {
            "file": "src/dds.imageio/ddsinput.cpp",
            "function": "DDSInput::readimg_tiles"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "98480878907942676926343174497403208797",
                "295115702753180903999134366909801252569",
                "214431112216280236342209904782424420169",
                "303958577378504720275984249360275349512",
                "161115287958132366956197562485094006083",
                "134835478272204265106079554144376033804",
                "16755371785108819856323384942326595736",
                "30847400770248294399117783446681181085",
                "226437485689310610116232538585288817987",
                "215769259561089912234485952059719597778",
                "142614682132908239917946999492166079761",
                "120817729636541300190815369270302640921",
                "334182795565937735180694326240879175664",
                "82577917944109695115386703021206753312",
                "87671651993833302198200380590545148240",
                "70056562080793713328593784437538694821",
                "205149522338304717272907233935992114868",
                "150923261754160082419778450551020012604",
                "136890523275455934251875713639928051290",
                "186075680253463603120634299438425459372",
                "139201785844797234177886587202914055135",
                "278095771963946436202498215349223438962",
                "241929148760010692897580521484604994680",
                "213548576105053062229520871667176651898",
                "172275492232004947745408601458916580098",
                "141128677241242062824455791760317874228",
                "215615353312605701030483927671424328063",
                "336497536390129410566712908674136808557",
                "158920401623820619161117053057605068328",
                "63622295856477162048750490117757122933",
                "27849106842856085229774122628810534187",
                "119844826840996550723058403099567790977",
                "1731046966844112898728705093531562473",
                "10592876073933143574400672896738792800",
                "254611942350562251030631246876408895784",
                "109823291454147719425904326828500784402",
                "256295184631373070653159833254780698731",
                "8882247144435812741196203676315949301",
                "79381783102939834159248640038406054744",
                "115488992470849375824179991143534513357",
                "131624847216418649034194485873504006716",
                "293360304532952597249375502699446218827",
                "60939431084698377486226921444692884429",
                "180618353274009744353363794299317767140",
                "7007340601495574246352473622888977729",
                "186692713003729936753499081456940740486",
                "136673624949920328307412600310358564081",
                "228414123601100241611120800579832698936",
                "197737393191778593633161340053126648031",
                "54858332078312135636959595265517453816",
                "226854389642862422349028338116321714251",
                "52009924268323830555260598915696840243",
                "142499487057468364080431859832693597572",
                "29090737387676226322349964503603141464",
                "339740301332938354676442642584314214593",
                "224537477646588664435826001086711824584",
                "279333201732065346083233222136609443408",
                "56778312546610557778523438401198592035",
                "206879139859247660624622538612870550210",
                "101919572830109550347117288551635087988",
                "108561663169216122198598277778308961378",
                "274889069779525623283210093663192182234",
                "305935058439147586117159893455456036797",
                "203898285190226506811446589767751266722",
                "231137322892361191475607992357960944537",
                "12758516980083023630404172520911645518",
                "204385822087736872494250677245304163872",
                "154679483434750625311432813347326089970",
                "154068128939305361399907329971586972079",
                "309957819064439629148360708568808657286",
                "132943177624556766871523950276644823111",
                "156309833814276266272485464861812451769",
                "149864350453812563199739139004049881259"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-7582-4945cfad",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/academysoftwarefoundation/openimageio/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2",
        "target": {
            "file": "src/dds.imageio/ddsinput.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "280901299082834952884431095314009101392",
            "length": 4384
        },
        "id": "CVE-2026-7582-5cf6a744",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/academysoftwarefoundation/openimageio/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2",
        "target": {
            "file": "src/dds.imageio/ddsinput.cpp",
            "function": "DDSInput::seek_subimage"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "274246697306922323067783515662634755449",
            "length": 215
        },
        "id": "CVE-2026-7582-668df106",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/academysoftwarefoundation/openimageio/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2",
        "target": {
            "file": "src/dds.imageio/ddsinput.cpp",
            "function": "DDSInput::readimg_scanlines"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "241823940527065513260894908766732187492",
            "length": 2120
        },
        "id": "CVE-2026-7582-8c4955ba",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/academysoftwarefoundation/openimageio/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2",
        "target": {
            "file": "src/dds.imageio/ddsinput.cpp",
            "function": "DDSInput::internal_readimg"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "235459127689790921342150403769934299925",
            "length": 445
        },
        "id": "CVE-2026-7582-af06f511",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/academysoftwarefoundation/openimageio/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2",
        "target": {
            "file": "src/dds.imageio/ddsinput.cpp",
            "function": "DDSInput::read_native_scanline"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "26606285743411465498979462907437603026",
            "length": 1527
        },
        "id": "CVE-2026-7582-af336d1a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/academysoftwarefoundation/openimageio/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2",
        "target": {
            "file": "src/dds.imageio/ddsinput.cpp",
            "function": "DDSInput::read_native_tile"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "179818250789147962985635136376935259434",
            "length": 1202
        },
        "id": "CVE-2026-7582-b318a458",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/academysoftwarefoundation/openimageio/commit/94ec2deec3e3bf2f2e2ff84d008e27425d626fe2",
        "target": {
            "file": "src/dds.imageio/ddsinput.cpp",
            "function": "DDSInput::internal_seek_subimage"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:09:20Z"