Heap-based buffer overflow in OpenEXR - #VU141339

 

Heap-based buffer overflow in OpenEXR - #VU141339

Published: August 8, 2026


Vulnerability identifier: #VU141339
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to heap-based buffer overflow in the exrmakepreview tool when parsing a crafted EXR file on ILP32 builds. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.

The issue is triggered by integer wraparound in Array2D size calculation from public dataWindow dimensions, and user interaction is required to process the crafted EXR file.


Affected software

OpenEXR

Remediation

Install security update from vendor's website.

OpenEXR - addressed in versions 3.2.11, 3.3.13, 3.4.14

External References

Related Security Bulletins