Use-After-Free Vulnerability in OpenEXR Affects Software Products by Academy Software Foundation
CVE-2025-64183
What is CVE-2025-64183?
A use-after-free vulnerability exists in the OpenEXR library’s Python interface, specifically within the PyObject_StealAttrString function implemented in pyOpenEXR_old.cpp. This flaw allows for a dangling pointer to be utilized after its memory has been deallocated, which can lead to accessing freed memory. As a result, applications that invoke APIs like PyLong_AsLong or PyFloat_AsDouble with these pointers may experience undefined behavior. The issue is present in various versions of OpenEXR, but has been patched in subsequent releases.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openexr >= 3.2.0, < 3.2.5 < 3.2.0, 3.2.5
openexr >= 3.3.0, < 3.3.6 < 3.3.0, 3.3.6
openexr >= 3.4.0, < 3.4.3 < 3.4.0, 3.4.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
