Bug 2428557 (CVE-2025-15506) - CVE-2025-15506 OpenColorIO: OpenColorIO: Local denial of service due to out-of-bounds read
Summary: CVE-2025-15506 OpenColorIO: OpenColorIO: Local denial of service due to out-o...
Keywords:
Status: NEW
Alias: CVE-2025-15506
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2428655 2428656 2428657 2428658
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-11 12:01 UTC by OSIDB Bzimport
Modified: 2026-01-12 11:45 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-11 12:01:17 UTC
A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is named ebdbb75123c9d5f4643e041314e2bc988a13f20d. To fix this issue, it is recommended to deploy a patch. The fix was added to the 2.5.1 milestone.


Note You need to log in before you can comment on or make changes to this bug.