PT-2026-81460 · Openexr · Openexr

·

CVE-2026-59982

·

Published

2026-08-25

·

Updated

2026-09-02

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions prior to 3.2.11 OpenEXR versions 3.3.0 through 3.3.12 OpenEXR versions 3.4.0 through 3.4.13
Description An issue exists where the TypedDeepImageChannel::row() function can return an out-of-bounds pointer when processing a crafted deep EXR image with a nonzero dataWindow origin. This occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, which may lead to a crash or limited information disclosure.
Recommendations Update to version 3.2.11. Update to version 3.3.13. Update to version 3.4.14.

Exploit

Fix

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59982
ECHO-9D66-05D6-7FC0
GHSA-6662-FQ6F-93MP
OPENSUSE-SU-2026:11612-1
OPENSUSE-SU-2026:21737-1

Affected Products

Openexr