A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is named ebdbb75123c9d5f4643e041314e2bc988a13f20d. To fix this issue, it is recommended to deploy a patch. The fix was added to the 2.5.1 milestone.
References
Configurations
No configuration.
History
11 Jan 2026, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-11 11:15
Updated : 2026-01-13 14:03
NVD link : CVE-2025-15506
Mitre link : CVE-2025-15506
CVE.ORG link : CVE-2025-15506
JSON object : View
Products Affected
No product.
