Home

Description

A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is named ebdbb75123c9d5f4643e041314e2bc988a13f20d. To fix this issue, it is recommended to deploy a patch. The fix was added to the 2.5.1 milestone.

PUBLISHED Reserved 2026-01-10 | Published 2026-01-11 | Updated 2026-01-11 | Assigner VulDB




MEDIUM: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
LOW: 3.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
LOW: 3.3CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
1.7AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C

Problem types

Out-of-Bounds Read

Memory Corruption

Product status

2.0
affected

2.1
affected

2.2
affected

2.3
affected

2.4
affected

2.5.0
affected

Timeline

2026-01-10:Advisory disclosed
2026-01-10:VulDB entry created
2026-01-10:VulDB entry last update

Credits

Oneafter (VulDB User) reporter

References

vuldb.com/?id.340444 (VDB-340444 | AcademySoftwareFoundation OpenColorIO FileRules.cpp ConvertToRegularExpression out-of-bounds) vdb-entry technical-description

vuldb.com/?ctiid.340444 (VDB-340444 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.733332 (Submit #733332 | AcademySoftwareFoundation OpenColorIO 1d77ecd Out-of-Bounds Read) third-party-advisory

github.com/AcademySoftwareFoundation/OpenColorIO/issues/2228 issue-tracking

github.com/AcademySoftwareFoundation/OpenColorIO/pull/2231 issue-tracking

github.com/oneafter/1225/blob/main/uaf exploit

github.com/...ommit/ebdbb75123c9d5f4643e041314e2bc988a13f20d patch

github.com/...emySoftwareFoundation/OpenColorIO/milestone/11 patch

cve.org (CVE-2025-15506)

nvd.nist.gov (CVE-2025-15506)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.