
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15506 is an out-of-bounds read vulnerability in AcademySoftwareFoundation OpenColorIO (OCIO) affecting versions up to and including 2.5.0. The flaw resides in the ConvertToRegularExpression function within src/OpenColorIO/FileRules.cpp, where an incorrect pointer index derived from a potentially longer transformed string (globString) is used to access the original, potentially shorter globPattern string, causing an out-of-bounds memory access. The vulnerability was reported on December 25, 2025, patched on January 11, 2026, and publicly disclosed the same day. It carries a CVSS v3.1 base score of 3.3 (Low) (GitHub Advisory, VulDB).
The root cause is classified as CWE-125 (Out-of-bounds Read) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The bug occurs in ThrowInvalidRegex (line 55 of FileRules.cpp): when processing a glob pattern with case-insensitive matching enabled, each alphabetic character is expanded to a [xX]-style bracket expression, producing a globString that is longer than the original globPattern. The code incorrectly passed globPattern + idx (an index into the longer globString) to ThrowInvalidRegex, which then attempted to read past the end of globPattern. The fix, applied in commit ebdbb75, changes the argument to &globString[idx] so the correct string is indexed. Exploitation requires local access and the ability to supply a malformed YAML configuration file containing a FileRules section with an invalid regular expression pattern (GitHub Issue #2228, GitHub PR #2231, Patch Commit).
Successful exploitation causes a denial-of-service condition by crashing the application through an out-of-bounds memory read, confirmed via AddressSanitizer (ASAN) reporting a heap-use-after-free/out-of-bounds access in strlen. There is no impact on confidentiality or data integrity — only availability is affected (CVSS availability impact: Low). The scope is limited to the local system running OpenColorIO, with no evidence of lateral movement potential or sensitive data exposure (GitHub Issue #2228, GitHub Advisory).
A public proof-of-concept exploit has been disclosed and is referenced in the CVE record (hosted at https://github.com/oneafter/1225/blob/main/uaf), though no evidence of active in-the-wild exploitation has been observed. The vulnerability requires low privileges and local access, limiting its practical attack surface. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the wild. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (VulDB, GitHub Advisory).
FileRules section with a glob pattern that, when case-insensitive expansion is applied, produces a globString longer than the original globPattern and includes an unmatched [ bracket character.Config::CreateFromStream() or equivalent API.OCIOYaml::Read processes the FileRules section, calling ValidateRegularExpression → BuildRegularExpression → ConvertToRegularExpression. When the malformed bracket expression is encountered, ThrowInvalidRegex is called with an out-of-bounds pointer into globPattern.globPattern buffer, triggering a crash (ASAN: heap-use-after-free/out-of-bounds read in strlen), resulting in application termination (GitHub Issue #2228, Patch Commit).OpenColorIO::ThrowInvalidRegex, ConvertToRegularExpression, or FileRules.cpp at line 55; ASAN output reporting heap-use-after-free or out-of-bounds read in strlen within the OpenColorIO process.FileRules sections containing unmatched bracket expressions in glob patterns.Config::CreateFromStream or OCIOYaml::Read with user-supplied input (GitHub Issue #2228).Upgrade AcademySoftwareFoundation OpenColorIO to version 2.5.1 or later, which includes the fix from commit ebdbb75123c9d5f4643e041314e2bc988a13f20d merged on January 11, 2026. Affected versions include 2.0, 2.1, 2.2, 2.3, 2.4, and 2.5.0. As a workaround where upgrading is not immediately possible, restrict local user access to OpenColorIO configuration files and avoid loading untrusted YAML configs containing FileRules sections (GitHub Advisory, GitHub Milestone).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."