Out-of-bounds write in OpenEXR - #VU141334
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and modify memory.
The vulnerability exists due to out-of-bounds write in the exrmetrics deep scanline sample-count handling when processing a crafted deep scanline EXR file on ILP32 builds. A remote attacker can trick the victim into opening a crafted file to cause a denial of service and modify memory.
User interaction is required to open the crafted file, and the issue is specific to ILP32 builds.