PT-2026-30663 · Openexr · Openexr

·

CVE-2026-34589

·

Published

2026-03-30

·

Updated

2026-09-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.2.0 through 3.2.6, 3.3.9, and 3.4.9
Description OpenEXR, an image storage format used in the motion picture industry, contains a flaw in the DWA lossy decoder. Specifically, the decoder uses signed 32-bit arithmetic to create temporary block pointers, which can overflow for large image widths. This overflow leads to out-of-bounds writes to memory outside the allocated row block, potentially leading to crashes or other unexpected behavior.
Recommendations Update to OpenEXR version 3.2.7 or later. Update to OpenEXR version 3.3.9 or later. Update to OpenEXR version 3.4.9 or later.

Exploit

Fix

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12079
CVE-2026-34589
ECHO-9812-7C70-A870
GHSA-P8XC-W3Q4-H64X
JLSEC-2026-149
OESA-2026-1840
OESA-2026-1841
OESA-2026-1842
OESA-2026-1843
OESA-2026-1844
OPENSUSE-SU-2026:10505-1
OPENSUSE-SU-2026:20605-1
PYSEC-2026-2848
SUSE-SU-2026:21372-1

Affected Products

Openexr