Integer overflow in OpenEXR - #VU141338
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the exrmaketiled ImageChannel Array2D allocation path when parsing a crafted EXR file. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
Only 32-bit ILP32 builds are vulnerable, and user interaction is required to process the crafted EXR file with the shipped exrmaketiled CLI tool.