top of page
perceptive_background_267k.jpg

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, …

Published:

25 augustus 2026 om 00:00:00

Alert date:

25 augustus 2026 om 21:01:54

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Supply Chain & Dependencies

OpenEXR, the reference implementation for the EXR image format widely used in the motion picture industry, contains a vulnerability in multiple versions. Affected versions include those before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. The flaw resides in the TypedDeepImageChannel::row() function, which can return an out-of-bounds pointer when processing a crafted deep EXR file with a nonzero dataWindow origin. The root cause is an API design issue where zero-based row access is combined with an absolute-coordinate-adjusted base pointer. Exploitation of this vulnerability can lead to application crashes or limited information disclosure. Fixed versions are 3.2.11, 3.3.13, and 3.4.14. Multiple commits have been published to the OpenEXR GitHub repository addressing this issue. A GitHub Security Advisory (GHSA-6662-fq6f-93mp) has also been published.

Technical details

Mitigation steps:

Affected products:

OpenEXR

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page