PT-2026-35476 · Julia · Openexr Jll

Published

2026-04-17

·

Updated

2026-04-17

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total sizes for attacker-controlled large counts across many parts, total sizes[ptr] wraps modulo 2^32. overall sample count is then derived from wrapped totals and used in samples[channel].resize(overall sample count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic unpack deep pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-141

Affected Products

Openexr Jll