PT-2025-40878 · Openexr+4 · Openexr+4

Published

2025-08-05

·

Updated

2026-01-27

·

CVE-2025-59732

CVSS v4.0

8.7

High

VectorAV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions OpenEXR versions prior to 8.0
Description An issue exists in decoding OpenEXR files that utilize DWAA or DWAB compression. The software implicitly assumes image height and width are divisible by 8. When this condition is not met, copy loops can write beyond allocated buffer boundaries, potentially leading to heap memory corruption. The td->uncompressed data buffer, allocated during the decode block process, is susceptible to being exceeded by the copy loop when the image dimensions are not multiples of 8. This can result in corruption of adjacent heap memory.
Recommendations Upgrade to version 8.0 or later.

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-12720
CVE-2025-59732
DSA-5985-1
DSA-6007-1
MGASA-2025-0306
USN-7982-1

Affected Products

Debian
Linuxmint
Openexr
Red Os
Ubuntu