Heap-based buffer overflow in OpenEXR - #VU141339
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in the exrmakepreview tool when parsing a crafted EXR file on ILP32 builds. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
The issue is triggered by integer wraparound in Array2D size calculation from public dataWindow dimensions, and user interaction is required to process the crafted EXR file.