#VU125326 Use of uninitialized resource in OpenEXR - CVE-2026-34543
Published: April 8, 2026
OpenEXR
OpenEXR
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized resource in undo_pxr24_impl and exr_uncompress_buffer when parsing a crafted PXR24 EXR file with a truncated zlib stream. A remote attacker can supply a specially crafted EXR file to disclose sensitive information.
The issue is triggered during decoding under default settings.