OpenEXR Vulnerability in DWA Decoder Affects Academy Software Foundation
CVE-2026-34589
8.4HIGH
What is CVE-2026-34589?
A flaw in the DWA lossy decoder of OpenEXR allows for the construction of temporary block pointers using signed 32-bit arithmetic, which can lead to memory overflow when processing large images. This overflow causes subsequent operations to reference invalid memory locations, resulting in potential application crashes or arbitrary code execution. The issue has been addressed in versions 3.2.7, 3.3.9, and 3.4.9, ensuring the safety of image processing applications using the OpenEXR format.
Affected Version(s)
openexr >= 3.2.0, < 3.2.7 < 3.2.0, 3.2.7
openexr >= 3.3.0, < 3.3.9 < 3.3.0, 3.3.9
openexr >= 3.4.0, < 3.4.9 < 3.4.0, 3.4.9
