PT-2026-29621 · Openexr · Openexr
Nicoppida
·
Published
2026-04-01
·
Updated
2026-05-11
·
CVE-2026-34544
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenEXR versions 3.4.0 through 3.4.7
Description
OpenEXR, an image storage format used in the motion picture industry, contains a flaw where a specially crafted EXR file (B44 or B44A format) can lead to an out-of-bounds write during decoding via the
exr decoding run() function. This can result in a crash or, potentially, corruption of heap allocations.Recommendations
Update to OpenEXR version 3.4.8 or later.
Fix
Integer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openexr