| Name | CVE-2026-42450 |
| Description | OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with `%s` into 64-byte stack buffers when parsing LUT data lines. Input comes from `lineBuffer[4096]`, so a crafted .spi3d file can overflow by ~4000 bytes on non-Windows. Version 2.5.2 fixes the issue. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1141498 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| opencolorio (PTS) | bullseye | 1.1.1~dfsg0-7 | fixed |
| bookworm | 2.1.2+dfsg1-4 | vulnerable |
| trixie | 2.1.3+dfsg-1.2 | vulnerable |
| forky, sid | 2.5.1+dfsg-4 | vulnerable |
The information below is based on the following data on fixed versions.
Notes
[trixie] - opencolorio <no-dsa> (Minor issue)
[bookworm] - opencolorio <postponed> (Minor issue)
[bullseye] - opencolorio <not-affected> (Vulnerable code introduced in 2.x rewrite; 1.1.1 Spi3D parser scans %f directly, no %s into stack buffers)
https://github.com/AcademySoftwareFoundation/OpenColorIO/security/advisories/GHSA-rxp3-rrgx-f547