PT-2026-81398 · Openexr · Openexr
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
OpenEXR versions prior to 3.2.11
OpenEXR versions 3.3.0 through 3.3.12
OpenEXR versions 3.4.0 through 3.4.13
Description
A crafted EXR file with a nonzero
dataWindow.min can cause the TypedFlatImageChannel::row() function to return an invalid heap pointer. This leads to out-of-bounds or use-after-free writes when an application writes rows through the FlatHalfChannel::row() function. This issue affects tools, converters, render pipeline components, or image-processing services that process untrusted EXR files using the FlatHalfChannel::row() function.Recommendations
Update to version 3.2.11.
Update to version 3.3.13.
Update to version 3.4.14.
Exploit
Fix
Memory Corruption
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openexr