PT-2026-81418 · Openexr · Openexr

·

CVE-2026-59187

·

Published

2026-08-25

·

Updated

2026-09-02

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions 3.3.0 through 3.3.12 OpenEXR versions 3.4.0 through 3.4.13
Description A heap out-of-bounds write occurs when the exrmetrics tool processes a specially crafted deep scanline EXR file. This happens when using pixel conversion options such as --pixelmode float or --bench, as the DeepSlice function requests FLOAT output while the backing sample buffers are allocated using the input HALF element size.
Recommendations Update OpenEXR versions 3.3.0 through 3.3.12 to version 3.3.13. Update OpenEXR versions 3.4.0 through 3.4.13 to version 3.4.14.

Exploit

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59187
ECHO-3020-8250-BA2B
GHSA-6JJ8-CXCR-J8HM
OPENSUSE-SU-2026:11612-1

Affected Products

Openexr