PT-2026-81462 · Openexr · Openexr
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenEXR versions 3.1.0 through 3.2.10
OpenEXR versions 3.3.0 through 3.3.12
OpenEXR versions 3.4.0 through 3.4.13
Description
On ILP32 builds, an out-of-bounds write occurs when processing a crafted B44-compressed scanline EXR. This happens because the logical scratch size truncates before allocation, and the
uncompress b44 impl() function writes using an attacker-controlled channel width, leading to memory corruption and denial of service.Recommendations
Update versions 3.1.0 through 3.2.10 to version 3.2.11.
Update versions 3.3.0 through 3.3.12 to version 3.3.13.
Update versions 3.4.0 through 3.4.13 to version 3.4.14.
Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openexr