PT-2026-33908 · Openexr · Openexr

Published

2026-04-21

·

Updated

2026-05-11

·

CVE-2026-40244

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.4.0 through 3.4.9 OpenEXR versions 3.3.0 through 3.3.9 OpenEXR versions 3.2.0 through 3.2.7
Description An integer overflow occurs in the reference implementation of the EXR image storage format. Specifically, the file internal dwa compressor.h:1722 performs the calculation curc->width * curc->height using int32 arithmetic without a (size t) cast.
Recommendations Update versions 3.4.0 through 3.4.9 to 3.4.10. Update versions 3.3.0 through 3.3.9 to 3.3.10. Update versions 3.2.0 through 3.2.7 to 3.2.8.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-40244
OESA-2026-2179
OESA-2026-2180
OESA-2026-2181
OPENSUSE-SU-2026:10665-1

Affected Products

Openexr