PT-2025-40879 · Openexr+4 · Openexr+4

CVE-2025-59733

·

Published

2025-08-25

·

Updated

2026-06-26

CVSS v4.0

8.7

High

VectorAV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OpenEXR versions prior to 8.0
Description An issue exists in decoding OpenEXR files that use DWAA or DWAB compression. The software makes an assumption that all image channels have the same pixel type and size, specifically expecting "B", "G", "R", and "A" channels when four channels are present. The dwa uncompress function calculates buffer sizes based on this assumption. If main color channels are set to a 4-byte type and additional channels of a 2-byte type are added, the calculation can result in exceeding the allocated buffer, potentially leading to issues. The vulnerable code is located in the decode header and dwa uncompress functions, and involves the td->uncompressed data buffer.
Recommendations Upgrade to version 8.0 or beyond.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12714
CVE-2025-59733
DSA-5985-1
DSA-6007-1
JLSEC-2026-646
MGASA-2025-0306
USN-7982-1

Affected Products

Debian
Linuxmint
Openexr
Red Os
Ubuntu