Skip to content

fix(cineon): validate bit depth against libcineon's supported set - #5283

Merged
lgritz merged 1 commit into
AcademySoftwareFoundation:mainfrom
lgritz:lg-cineonbitdepth
Jul 6, 2026
Merged

fix(cineon): validate bit depth against libcineon's supported set#5283
lgritz merged 1 commit into
AcademySoftwareFoundation:mainfrom
lgritz:lg-cineonbitdepth

Conversation

@lgritz

@lgritz lgritz commented Jul 1, 2026

Copy link
Copy Markdown
Collaborator

CineonInput::open() accepted any per-channel bit depth in [1,32], but libcineon's ComponentDataSize()/ComponentByteCount() only recognize {8,10,12,16,32,64} and assert(0) on anything else. A crafted file with an unsupported bit depth (e.g. 26) passed the OIIO-side check and then aborted deep inside the vendored library instead of failing cleanly.

Tighten the check to libcineon's actual whitelist so bogus bit depths are rejected with a proper errorfmt() before ever reaching the vendored code. Adds a regression fixture (broken_bitdepth2.cin) to the cineon testsuite.

Assisted-by: Claude Code / Sonnet 5

CineonInput::open() accepted any per-channel bit depth in [1,32], but
libcineon's ComponentDataSize()/ComponentByteCount() only recognize
{8,10,12,16,32,64} and assert(0) on anything else. A crafted file with
an unsupported bit depth (e.g. 26) passed the OIIO-side check and then
aborted deep inside the vendored library instead of failing cleanly.

Tighten the check to libcineon's actual whitelist so bogus bit depths
are rejected with a proper errorfmt() before ever reaching the vendored
code. Adds a regression fixture (broken_bitdepth2.cin) to the cineon
testsuite.

Assisted-by: Claude Code / Sonnet 5

Signed-off-by: Larry Gritz <lg@larrygritz.com>

@grdanny grdanny left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks reasonable to me.

@lgritz
lgritz merged commit 6f2b2e8 into AcademySoftwareFoundation:main Jul 6, 2026
28 checks passed
@lgritz
lgritz deleted the lg-cineonbitdepth branch July 6, 2026 00:19
lgritz added a commit to lgritz/OpenImageIO that referenced this pull request Jul 15, 2026
…ademySoftwareFoundation#5283)

CineonInput::open() accepted any per-channel bit depth in [1,32], but
libcineon's ComponentDataSize()/ComponentByteCount() only recognize
{8,10,12,16,32,64} and assert(0) on anything else. A crafted file with
an unsupported bit depth (e.g. 26) passed the OIIO-side check and then
aborted deep inside the vendored library instead of failing cleanly.

Tighten the check to libcineon's actual whitelist so bogus bit depths
are rejected with a proper errorfmt() before ever reaching the vendored
code. Adds a regression fixture (broken_bitdepth2.cin) to the cineon
testsuite.

Assisted-by: Claude Code / Sonnet 5

Signed-off-by: Larry Gritz <lg@larrygritz.com>
lgritz added a commit to lgritz/OpenImageIO that referenced this pull request Jul 15, 2026
…ademySoftwareFoundation#5283)

CineonInput::open() accepted any per-channel bit depth in [1,32], but
libcineon's ComponentDataSize()/ComponentByteCount() only recognize
{8,10,12,16,32,64} and assert(0) on anything else. A crafted file with
an unsupported bit depth (e.g. 26) passed the OIIO-side check and then
aborted deep inside the vendored library instead of failing cleanly.

Tighten the check to libcineon's actual whitelist so bogus bit depths
are rejected with a proper errorfmt() before ever reaching the vendored
code. Adds a regression fixture (broken_bitdepth2.cin) to the cineon
testsuite.

Assisted-by: Claude Code / Sonnet 5

Signed-off-by: Larry Gritz <lg@larrygritz.com>
@lgritz

lgritz commented Jul 17, 2026

Copy link
Copy Markdown
Collaborator Author

CVE-2026-63638

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants