Heap Out-of-Bounds Write in OpenEXR Image Processing Software by Academy Software Foundation
CVE-2026-59187
7.1HIGH
What is CVE-2026-59187?
OpenEXR, the widely-utilized implementation and specification for the EXR image format in the motion picture industry, is prone to a heap out-of-bounds write vulnerability. This issue arises during the processing of crafted deep scanline EXR images when using specific pixel conversion options, leading to mismanagement of sample buffer allocations. This security flaw affects several versions, including 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, and has been addressed in subsequent releases.
Affected Version(s)
openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13
openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14
