PT-2025-40878 · Openexr+4 · Openexr+4
Published
2025-08-05
·
Updated
2026-01-27
·
CVE-2025-59732
CVSS v4.0
8.7
High
| Vector | AV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenEXR versions prior to 8.0
Description
An issue exists in decoding OpenEXR files that utilize DWAA or DWAB compression. The software implicitly assumes image height and width are divisible by 8. When this condition is not met, copy loops can write beyond allocated buffer boundaries, potentially leading to heap memory corruption. The
td->uncompressed data buffer, allocated during the decode block process, is susceptible to being exceeded by the copy loop when the image dimensions are not multiples of 8. This can result in corruption of adjacent heap memory.Recommendations
Upgrade to version 8.0 or later.
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Openexr
Red Os
Ubuntu