Integer overflow in OpenEXR - CVE-2026-40250
Published: April 20, 2026
OpenEXR
OpenEXR
Description
The vulnerability allows a remote attacker to corrupt the heap.
The vulnerability exists due to integer overflow or wraparound in DwaCompressor_uncompress() in internal_dwa_compressor.h when parsing a crafted DWAA/DWAB EXR file. A remote attacker can trick the victim into opening a crafted file to corrupt the heap.
User interaction is required to open a crafted file.