PT-2025-46202 · Openexr · Openexr

CVE-2025-64182

·

Published

2025-11-10

·

Updated

2026-07-13

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.2.0 through 3.2.4 OpenEXR versions 3.3.0 through 3.3.5 OpenEXR versions 3.4.0 through 3.4.2
Description OpenEXR is an image storage format used in the motion picture industry. A memory safety issue exists in the legacy OpenEXR Python adapter (the deprecated OpenEXR.InputFile wrapper). This issue can lead to crashes and potential code execution when processing attacker-controlled EXR files or crafted Python objects. Specifically, integer overflow and unchecked allocation within the InputFile.channel() and InputFile.channels() functions can cause a heap overflow (on 32-bit systems) or a NULL dereference (on 64-bit systems).
Recommendations Update to OpenEXR version 3.2.5 or later. Update to OpenEXR version 3.3.6 or later. Update to OpenEXR version 3.4.3 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64182
GHSA-VH63-9MQX-WMJR
OPENSUSE-SU-2025:15741-1
PYSEC-2026-2851

Affected Products

Openexr