Memory Allocation Vulnerability in OpenEXR 3.3.2 by Academy Software Foundation
CVE-2025-48074

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 August 2025

What is CVE-2025-48074?

A vulnerability exists in OpenEXR version 3.3.2 that allows applications to trust unvalidated dataWindow size values from file headers. This oversight can result in excessive memory allocation, which may lead to performance degradation when processing potentially malicious EXR files. Users are encouraged to upgrade to version 3.3.3, where this issue has been addressed.

Affected Version(s)

openexr >= 3.3.2, < 3.3.3

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48074 : Memory Allocation Vulnerability in OpenEXR 3.3.2 by Academy Software Foundation