CVE 8.8 HIGH

OpenEXR is Vulnerable to Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API_CVE-2026-41142

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

AI Analysis

Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API

Basic Information

ID CVE-2026-41142
Source GitHub_M
Published May 7, 2026 at 03:58

Affected Product

Vendor AcademySoftwareFoundation
Product openexr
Version >= 3.0.0, < 3.2.9
Affected Versions AcademySoftwareFoundation openexr >= 3.0.0, < 3.2.9
AcademySoftwareFoundation openexr >= 3.3.0, < 3.3.11
AcademySoftwareFoundation openexr >= 3.4.0, < 3.4.11

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor AcademySoftwareFoundation
Product OpenEXR
Version 3.0.0-3.2.8, 3.3.0-3.3.10, 3.4.0-3.4.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.