Heap-based buffer overflow in OpenEXR - #VU141337
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in the exrmultipart convert tool when parsing a crafted EXR file on ILP32 builds. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
The issue is triggered by an allocation-size truncation in channelstore sizing, and user interaction is required to process the crafted EXR file.