PT-2026-21650 · Openexr · Openexr

Jungwoojjing

·

Published

2026-02-24

·

Updated

2026-04-06

·

CVE-2026-26981

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.3.0 through 3.3.6 OpenEXR versions 3.4.0 through 3.4.4
Description OpenEXR is an image storage format used in the motion picture industry. A heap-buffer-overflow (out-of-bounds read) can occur in the istream nonparallel read function within the ImfContextInit.cpp file when processing a specially crafted, malformed EXR file using a memory-mapped IStream. This happens because a negative value resulting from a signed integer subtraction is converted to size t, leading to an excessively large length being used in a memcpy operation.
Recommendations Update to OpenEXR version 3.3.7 or later. Update to OpenEXR version 3.4.5 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-26981
GHSA-Q6VJ-WXVF-5M8C
OPENSUSE-SU-2026:10272-1

Affected Products

Openexr