OpenEXR Vulnerability in DWA Decoder Affects Academy Software Foundation
CVE-2026-34589

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-34589?

A flaw in the DWA lossy decoder of OpenEXR allows for the construction of temporary block pointers using signed 32-bit arithmetic, which can lead to memory overflow when processing large images. This overflow causes subsequent operations to reference invalid memory locations, resulting in potential application crashes or arbitrary code execution. The issue has been addressed in versions 3.2.7, 3.3.9, and 3.4.9, ensuring the safety of image processing applications using the OpenEXR format.

Affected Version(s)

openexr >= 3.2.0, < 3.2.7 < 3.2.0, 3.2.7

openexr >= 3.3.0, < 3.3.9 < 3.3.0, 3.3.9

openexr >= 3.4.0, < 3.4.9 < 3.4.0, 3.4.9

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.