CVE-2022-41649
NixOS vulnerability analysis and mitigation

Overview

A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. The vulnerability, identified as CVE-2022-41649, was discovered by Cisco Talos and disclosed on December 22, 2022. A specially-crafted TIFF file can trigger this vulnerability, which affects OpenImageIO versions up to v2.3.19.0 (Talos Report).

Technical details

The vulnerability occurs during the processing of IPTC data in TIFF images. When handling IPTC data, the code incorrectly calculates buffer sizes when casting from char to uint32_t, leading to a heap buffer overflow. This results in reading adjacent heap memory beyond the allocated buffer boundaries. The vulnerability has been assigned a CVSS score of 7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) and is classified as CWE-125 (Out-of-bounds Read) (Talos Report).

Impact

When exploited, this vulnerability can cause a read of adjacent heap memory, potentially leaking sensitive process information. The impact is primarily focused on information disclosure, which could be leveraged by attackers to gather sensitive data about the running process (Talos Report).

Mitigation and workarounds

The vulnerability has been fixed in the OpenImageIO master branch (Commit ID 9aeec7a). Users are advised to upgrade to the patched versions. Multiple distributions have released security updates, including Debian with version 2.2.10.1+dfsg-1+deb11u1 for bullseye and version 2.0.5~dfsg0-1+deb10u2 for buster (Debian Advisory, Debian Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • rhel10::firefox-flatpak
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • rhel10::thunderbird-flatpak
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management