Use of uninitialized resource in OpenEXR - #VU141331
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized resource in the HTJ2K decoder channel map handling when parsing a crafted HTJ2K-compressed EXR file. A remote attacker can supply a malformed EXR file with duplicate but in-range channel map entries to disclose sensitive information.
User interaction is required to open or decode a crafted EXR file.