#VU125322 Out-of-bounds read in OpenEXR - CVE-2025-48072
Published: April 8, 2026
OpenEXR
OpenEXR
Description
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in LossyDctDecoder_execute when decompressing DWAA-packed scan-line EXR files with a maliciously forged chunk. A remote attacker can supply a specially crafted EXR file to cause a denial of service and disclose sensitive information.
The issue occurs when SSE2 is enabled and can be triggered with non-block aligned chunks whose width or height is not a multiple of 8.