PT-2026-29621 · Openexr · Openexr

Nicoppida

·

Published

2026-04-01

·

Updated

2026-05-11

·

CVE-2026-34544

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.4.0 through 3.4.7
Description OpenEXR, an image storage format used in the motion picture industry, contains a flaw where a specially crafted EXR file (B44 or B44A format) can lead to an out-of-bounds write during decoding via the exr decoding run() function. This can result in a crash or, potentially, corruption of heap allocations.
Recommendations Update to OpenEXR version 3.4.8 or later.

Fix

Integer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-34544
GHSA-H762-RHV3-H25V
OPENSUSE-SU-2026:10505-1

Affected Products

Openexr