Out-of-bounds write in OpenEXR - CVE-2026-59984
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the B44 scanline decode path reached through the public C++ Imf::InputFile::readPixels() API when parsing a crafted B44-compressed scanline EXR file on 32-bit ILP32 builds. A remote attacker can trick the victim into opening a crafted file to cause a denial of service.
Only 32-bit ILP32 builds are affected, and user interaction is required to open the crafted EXR file.