Heap-based buffer overflow in OpenEXR - CVE-2026-68515
Published: August 8, 2026 / Updated: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or corrupt memory.
The vulnerability exists due to a heap-based buffer overflow in the exrmultiview utility when processing two attacker-supplied scanline EXR files whose combined data window is not aligned to a view's channel subsampling. A remote attacker can supply crafted EXR inputs to trigger a heap out-of-bounds write and cause a denial of service or corrupt memory.
User interaction is required to open or process the crafted EXR files.
Affected software
Red Hat Enterprise Linux for Power, little endian
OpenEXR (Red Hat package)
How to mitigate CVE-2026-68515
OpenEXR (Red Hat package) - update to 3.1.10-8.el10_2.4