Out-of-Bounds Read Vulnerability in OpenEXR by Academy Software Foundation
CVE-2026-59983
5.5MEDIUM
What is CVE-2026-59983?
A significant vulnerability has been identified in the OpenEXR library, which is crucial in handling the EXR image format commonly found in the motion picture industry. Certain versions of OpenEXR are susceptible to an out-of-bounds read when processing specially crafted uncompressed deep-tile EXR files. The flaw arises during the sample-count table size calculation, which can lead to unexpected behavior, potentially resulting in denial of service. Recommended versions to mitigate this issue include OpenEXR 3.2.11, 3.3.13, and 3.4.14.
Affected Version(s)
openexr < 3.2.11 < 3.2.11
openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13
openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14
