PT-2026-38333 · Openexr+1 · Openexr+1

·

CVE-2026-41142

·

Published

2026-04-22

·

Updated

2026-09-02

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.0.0 through 3.2.8 OpenEXR versions 3.3.0 through 3.3.10 OpenEXR versions 3.4.0 through 3.4.10
Description An integer overflow exists in the ImageChannel::resize() function, which can lead to a heap out-of-bounds (OOB) write—a condition where data is written outside the boundaries of the allocated memory buffer—via the OpenEXRUtil public API.
Recommendations Update to version 3.2.9 Update to version 3.3.11 Update to version 3.4.11

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38498
ALSA-2026:38499
BDU:2026-12852
CVE-2026-41142
ECHO-DD6A-E30B-958D
GHSA-M25W-72CJ-Q6MG
JLSEC-2026-809
OESA-2026-2364
OESA-2026-2365
OESA-2026-2366
OESA-2026-2536
OPENSUSE-SU-2026:10772-1
OPENSUSE-SU-2026:20755-1
RHSA-2026:38498
RHSA-2026:38499
RHSA-2026:39024
RHSA-2026:39025
RHSA-2026:39026
RHSA-2026:39027
SUSE-SU-2026:2114-1
SUSE-SU-2026:21796-1

Affected Products

Openexr
Rocky Linux