Integer Overflow to Buffer Overflow in OpenEXR - #VU141327
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an integer overflow to buffer overflow in deep EXR decoding of sample_count_table_size when parsing a crafted deep EXR file. A remote attacker can supply a specially crafted file to cause memory corruption.
User interaction is required to open or process a crafted deep EXR file. Only ILP32 or other 32-bit size_t builds are vulnerable.