What happened
The Academy Software Foundation project released OpenImageIO 3.1.16.0 on August 1. Its notes list eight assigned CVEs affecting Cineon, EXR, GIF/Targa, IFF, PSD and TIFF paths, alongside additional validation for BMP, DDS, DPX, HDR, JPEG 2000, JPEG XL, RAW, SGI and other readers.
The release adds a global per-dimension resolution limit intended to guard against decompression-bomb attacks, applies a LibRaw memory cap before unpacking and introduces libFuzzer infrastructure for file-format readers. It also fixes a multithreaded ImageBuf data race. These are library-level changes: an application benefits only when it actually ships or loads a patched OpenImageIO build.
Why it matters
Media files are inputs, not harmless pictures. A studio that receives EXR, PSD, TIFF or RAW files from clients, vendors or public links exposes its ingest machines and render nodes to parsers before anyone judges the image visually. Dependency inventory and sandboxed ingest matter as much as the visible application version.
What we're watching
We are watching for downstream rebuilds and backports, distribution advisories, CVSS scoring and any evidence of exploitation. The release notes document fixed code paths; they do not prove that every OpenImageIO-based application was exploitable in its default configuration.