Out-of-Bounds Write in OpenEXR Image Format by Academy Software Foundation
CVE-2026-34544
8.4HIGH
What is CVE-2026-34544?
A vulnerability in OpenEXR, an image storage format widely used in the motion picture industry, allows attackers to exploit crafted B44 or B44A EXR files. This can result in an out-of-bounds write when decoded through the exr_decoding_run() function, potentially leading to application crashes or corruption of adjacent heap memory. This issue has been resolved in version 3.4.8, which users are advised to upgrade to in order to mitigate risks associated with this vulnerability.
Affected Version(s)
openexr >= 3.4.0, < 3.4.8
