Heap Buffer Overflow in OpenEXR Python Bindings from Academy Software Foundation
CVE-2026-68514
5.5MEDIUM
What is CVE-2026-68514?
The OpenEXR Python bindings have a vulnerability that allows for a heap buffer overflow when processing a specifically crafted deep scanline EXR file. This issue arises from the wrapper incorrectly handling literal and prefixed RGB channels, which leads to memory corruption and crashes during decoding. Users are encouraged to upgrade to versions 3.3.13 or 3.4.14 to mitigate this risk.
Affected Version(s)
openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13
openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14
