Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40250

Опубликовано: 21 апр. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, internal_dwa_compressor.h:1040 performs chan->width * chan->bytes_per_element in int32 arithmetic without a (size_t) cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses internal_dwa_compressor.h:1040.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.8 (исключая)
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Версия от 3.3.0 (включая) до 3.3.10 (исключая)
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Версия от 3.4.0 (включая) до 3.4.10 (исключая)

EPSS

Процентиль: 37%
0.0045
Низкий

7.1 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan->width * chan->bytes_per_element` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1040`.

CVSS3: 6.8
redhat
4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan->width * chan->bytes_per_element` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1040`.

CVSS3: 7.1
debian
4 месяца назад

OpenEXR provides the specification and reference implementation of the ...

suse-cvrf
3 месяца назад

Security update for openexr

suse-cvrf
3 месяца назад

Security update for openexr

EPSS

Процентиль: 37%
0.0045
Низкий

7.1 High

CVSS3

Дефекты

CWE-190