PT-2026-33908 · Openexr · Openexr

CVE-2026-40244

·

Published

2026-04-21

·

Updated

2026-09-02

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.4.0 through 3.4.9 OpenEXR versions 3.3.0 through 3.3.9 OpenEXR versions 3.2.0 through 3.2.7
Description An integer overflow occurs in the reference implementation of the EXR image storage format. Specifically, the file internal dwa compressor.h:1722 performs the calculation curc->width * curc->height using int32 arithmetic without a (size t) cast.
Recommendations Update versions 3.4.0 through 3.4.9 to 3.4.10. Update versions 3.3.0 through 3.3.9 to 3.3.10. Update versions 3.2.0 through 3.2.7 to 3.2.8.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40244
ECHO-BEF0-7838-A483
GHSA-J526-66F6-FXHX
JLSEC-2026-807
OESA-2026-2179
OESA-2026-2180
OESA-2026-2181
OPENSUSE-SU-2026:10665-1
OPENSUSE-SU-2026:20652-1
SUSE-SU-2026:1712-1
SUSE-SU-2026:21433-1

Affected Products

Openexr