Out-of-Bounds Write in OpenEXR Image Format by Academy Software Foundation
CVE-2026-34544

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34544?

A vulnerability in OpenEXR, an image storage format widely used in the motion picture industry, allows attackers to exploit crafted B44 or B44A EXR files. This can result in an out-of-bounds write when decoded through the exr_decoding_run() function, potentially leading to application crashes or corruption of adjacent heap memory. This issue has been resolved in version 3.4.8, which users are advised to upgrade to in order to mitigate risks associated with this vulnerability.

Affected Version(s)

openexr >= 3.4.0, < 3.4.8

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.