PT-2026-81118 · Openexr · Openexr

·

CVE-2026-59183

·

Published

2026-08-25

·

Updated

2026-09-02

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.1.0 through 3.2.10 OpenEXR versions 3.3.0 through 3.3.12 OpenEXR versions 3.4.0 through 3.4.13
Description An integer overflow occurs during an int32 t multiplication within the unpack sample table() function of OpenEXRCore when decoding a specially crafted deep tiled EXR file. This overflow happens in the standard decoding path exr decoding run, resulting in an invalid pointer that causes a read from an unmapped memory address and a subsequent application crash.
Recommendations Update versions 3.1.0 through 3.2.10 to version 3.2.11. Update versions 3.3.0 through 3.3.12 to version 3.3.13. Update versions 3.4.0 through 3.4.13 to version 3.4.14.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59183
ECHO-383B-727D-C60A
GHSA-RQP5-PMWM-WJ6X
OPENSUSE-SU-2026:11612-1
OPENSUSE-SU-2026:21737-1

Affected Products

Openexr