CVE-2025-15506
Publication date 11 January 2026
Last updated 13 January 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A vulnerability was found in AcademySoftwareFoundation OpenColorIO up to 2.5.0. This issue affects the function ConvertToRegularExpression of the file src/OpenColorIO/FileRules.cpp. Performing a manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is named ebdbb75123c9d5f4643e041314e2bc988a13f20d. To fix this issue, it is recommended to deploy a patch. The fix was added to the 2.5.1 milestone.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| opencolorio | 25.10 questing |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | Low |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2025-15506
- https://github.com/AcademySoftwareFoundation/OpenColorIO/issues/2228
- https://github.com/AcademySoftwareFoundation/OpenColorIO/pull/2231
- https://github.com/AcademySoftwareFoundation/OpenColorIO/milestone/11
- https://github.com/cozdas/OpenColorIO/commit/ebdbb75123c9d5f4643e041314e2bc988a13f20d
- https://github.com/oneafter/1225/blob/main/uaf
- https://vuldb.com/?ctiid.340444
- https://vuldb.com/?id.340444
- https://vuldb.com/?submit.733332