PT-2026-33909 · Openexr · Openexr

CVE-2026-40250

·

Published

2026-04-21

·

Updated

2026-07-17

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.4.0 through 3.4.9 OpenEXR versions 3.3.0 through 3.3.9 OpenEXR versions 3.2.0 through 3.2.7
Description An integer overflow occurs in the reference implementation of the EXR image storage format. The issue exists in internal dwa compressor.h:1040 where the calculation chan->width * chan->bytes per element is performed using int32 arithmetic without a (size t) cast.
Recommendations Update versions 3.4.0 through 3.4.9 to 3.4.10. Update versions 3.3.0 through 3.3.9 to 3.3.10. Update versions 3.2.0 through 3.2.7 to 3.2.8.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40250
ECHO-93C5-5788-8DA1
GHSA-M5QW-23X2-6PHJ
OESA-2026-2179
OESA-2026-2180
OESA-2026-2181
OPENSUSE-SU-2026:10665-1
OPENSUSE-SU-2026:20652-1
SUSE-SU-2026:1712-1
SUSE-SU-2026:21433-1

Affected Products

Openexr