Heap Out-of-Bounds Write in OpenEXR's exrmultiview Utility
CVE-2026-68515

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-68515?

The OpenEXR image format tool, especially the exrmultiview command, has a vulnerability that may allow attackers to write beyond allocated memory. This occurs due to improper handling of alignment in the combining of two EXR files, leading to potential manipulation through normal processing paths. The issue is triggered when using crafted but valid input files, making it critical to update to versions 3.2.11, 3.3.13, or 3.4.14 to mitigate this risk.

Affected Version(s)

openexr >= 3.3.0, < 3.3.13 < 3.3.0, 3.3.13

openexr >= 3.4.0, < 3.4.14 < 3.4.0, 3.4.14

openexr < 3.2.11 < 3.2.11

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.