Out-of-bounds write in OpenEXR - #VU141334

 

Out-of-bounds write in OpenEXR - #VU141334

Published: August 8, 2026


Vulnerability identifier: #VU141334
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service and modify memory.

The vulnerability exists due to out-of-bounds write in the exrmetrics deep scanline sample-count handling when processing a crafted deep scanline EXR file on ILP32 builds. A remote attacker can trick the victim into opening a crafted file to cause a denial of service and modify memory.

User interaction is required to open the crafted file, and the issue is specific to ILP32 builds.


Affected software

OpenEXR

Remediation

Install security update from vendor's website.

OpenEXR - addressed in versions 3.3.13, 3.4.14

External References

Related Security Bulletins