Heap-based buffer overflow in OpenEXR - CVE-2026-68515

 

Heap-based buffer overflow in OpenEXR - CVE-2026-68515

Published: August 8, 2026 / Updated: August 8, 2026


Vulnerability identifier: #VU141348
CSH Severity: High
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68515
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service or corrupt memory.

The vulnerability exists due to a heap-based buffer overflow in the exrmultiview utility when processing two attacker-supplied scanline EXR files whose combined data window is not aligned to a view's channel subsampling. A remote attacker can supply crafted EXR inputs to trigger a heap out-of-bounds write and cause a denial of service or corrupt memory.

User interaction is required to open or process the crafted EXR files.


Affected software

OpenEXR
Red Hat Enterprise Linux for Power, little endian
OpenEXR (Red Hat package)

How to mitigate CVE-2026-68515

Install security update from vendor's website.

OpenEXR - addressed in versions 3.2.11, 3.3.13, 3.4.14
OpenEXR (Red Hat package) - update to 3.1.10-8.el10_2.4

External References

Related Security Bulletins