← Terug naar overzicht

A vulnerability in OpenEXR, the reference implementation for the EXR image format used in the motion picture industry, allows crafted EXR files with a nonzero dataWindow.min to cause TypedFlatImageChannel::row() to return an invalid heap pointer. This results in out-of-bounds or use-after-free writes when an application writes rows through FlatHalfChannel::row(). Affected versions include those before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. Tools, converters, render pipeline components, and image-processing services that accept untrusted EXR files are at risk. The vulnerability can be triggered by processing maliciously crafted EXR files from untrusted sources. Fixes have been released in versions 3.2.11, 3.3.13, and 3.4.14. Users are advised to upgrade to the patched versions immediately to mitigate the risk of memory corruption attacks.

Affected products

  • OpenEXR

Related CVE's

  • CVE-2026-59184

Categories

  • Enterprise Applications
  • Supply Chain & Dependencies