Integer overflow in OpenEXR - CVE-2026-54920
Published: June 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in OpenEXRUtil Image::resize() and Image::clearLevels() when processing crafted Imath::Box2i data window coordinates through the public API. A remote attacker can supply crafted coordinate values that trigger exception cleanup and invalid deletion of uninitialized ImageLevel pointers to cause a denial of service.
The issue is confirmed to crash the process through an invalid delete of uninitialized pointer entries during exception cleanup, while remote code execution was not confirmed.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Desktop Applications Module
libIlmImf-Imf_2_1-21-debuginfo
OpenEXR
libIlmImf-Imf_2_1-21
openexr-debuginfo
openexr-debugsource
openexr-devel
libIlmImfUtil-2_2-23
libIlmImfUtil-2_2-23-debuginfo
libIlmImf-2_2-23
libIlmImf-2_2-23-debuginfo
How to mitigate CVE-2026-54920
libIlmImf-Imf_2_1-21-debuginfo - update to 2.1.0-6.48.1
OpenEXR - update to 2.1.0-6.48.1
libIlmImf-Imf_2_1-21 - update to 2.1.0-6.48.1
openexr-debuginfo - addressed in versions 2.1.0-6.48.1, 2.2.1-150000.3.52.1
openexr-debugsource - addressed in versions 2.1.0-6.48.1, 2.2.1-150000.3.52.1
openexr-devel - addressed in versions 2.1.0-6.48.1, 2.2.1-150000.3.52.1
libIlmImfUtil-2_2-23 - update to 2.2.1-150000.3.52.1
libIlmImfUtil-2_2-23-debuginfo - update to 2.2.1-150000.3.52.1
libIlmImf-2_2-23 - update to 2.2.1-150000.3.52.1
libIlmImf-2_2-23-debuginfo - update to 2.2.1-150000.3.52.1