PT-2026-29622 · Openexr · Openexr

·

CVE-2026-34545

·

Published

2026-04-01

·

Updated

2026-07-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.4.0 through 3.4.6
Description OpenEXR, a specification and reference implementation of the EXR file format used in the motion picture industry, contains a flaw. A crafted .exr file utilizing HTJ2K compression and a channel width of 32768 can cause a heap buffer overflow when decoded by applications. This overflow occurs due to a write primitive of 2 or 4 bytes per iteration, repeating for each pixel exceeding the overflow point. This can lead to remote code execution.
Recommendations Update to OpenEXR version 3.4.7 or later.

Exploit

Fix

Integer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34545
ECHO-DB67-6198-EA48
GHSA-GHFJ-FX47-WG97
JLSEC-2026-147
OPENSUSE-SU-2026:10505-1

Affected Products

Openexr