Out-of-bounds Vulnerability in OpenEXR Image Processing Software from Academy Software Foundation
CVE-2026-59982
7.1HIGH
What is CVE-2026-59982?
The OpenEXR image processing software, widely adopted in the film industry, contains an out-of-bounds vulnerability that can be exploited when processing deep EXR files with specific configurations. This flaw specifically arises in the TypedDeepImageChannel::row() method, where the combination of a zero-based row access pattern and an absolute-coordinate-adjusted base pointer can lead to a crash or potentially expose sensitive information. Affected versions include those prior to 3.2.11 and certain releases in the 3.3 and 3.4 series. Mitigation is available in subsequent updates.
Affected Version(s)
openexr >= 3.1.0, < 3.2.11 < 3.1.0, 3.2.11
openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13
openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14
