PT-2026-81496 · Openexr · Openexr

·

CVE-2026-68515

·

Published

2026-08-25

·

Updated

2026-09-02

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEXR versions prior to 3.2.11 OpenEXR versions 3.3.0 through 3.3.12 OpenEXR versions 3.4.0 through 3.4.13
Description The exrmultiview utility can perform a heap out-of-bounds write when combining two valid scanline EXR files if the union dataWindow is not aligned to the channel subsampling of one view. The issue occurs because the utility allocates sampled channel storage using a truncated union width / xSampling and subsequently reads the sampled input through a Slice based on the misaligned union window. This can be triggered during normal processing of crafted but valid input files.
Recommendations Update to version 3.2.11. Update to version 3.3.13. Update to version 3.4.14.

Exploit

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97646
CVE-2026-68515
ECHO-4A45-30EC-EEF0
GHSA-GJF7-WJJW-XQ56
OPENSUSE-SU-2026:11612-1
OPENSUSE-SU-2026:21737-1

Affected Products

Openexr