Integer overflow in OpenEXR - CVE-2026-40244
Published: April 20, 2026
OpenEXR
OpenEXR
Description
The vulnerability allows a remote attacker to corrupt heap memory.
The vulnerability exists due to integer overflow in DWA setupChannelData planarUncRle pointer arithmetic when parsing a crafted EXR file. A remote attacker can supply a crafted DWAA/DWAB EXR file with large dimensions to corrupt heap memory.
User interaction is required to open the crafted file, and the issue is triggered on non-DCT channels, including UINT or single-channel layouts.