Out-of-bounds write in OpenEXR - #VU141333
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and modify memory.
The vulnerability exists due to out-of-bounds write in the exrmetrics deep tiled sample-count handling when parsing a crafted deep tiled EXR file. A remote attacker can trick the victim into opening a crafted file to cause a denial of service and modify memory.
The issue is specific to ILP32 builds and requires user interaction to process an untrusted deep tiled EXR file with the shipped command-line tool.