Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34544

Опубликовано: 01 апр. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.

A flaw was found in OpenEXR, an image storage format for the motion picture industry. A remote attacker or local user could exploit this vulnerability by providing a specially crafted B44 or B44A EXR file. This crafted file can cause an out-of-bounds write during file decoding, which may lead to memory corruption and potentially arbitrary code execution or, most likely, an application crash (Denial of Service).

Отчет

This Moderate impact flaw in OpenEXR affects Red Hat products that process EXR image files. A specially crafted B44 or B44A EXR file can trigger an out-of-bounds write during decoding, potentially leading to memory corruption and application crashes. Exploitation requires user interaction with a malicious file.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted B44 or B44A EXR image files with applications linked against the OpenEXR library. Restricting the source of EXR files to trusted origins can reduce the risk of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10openexrAffected
Red Hat Enterprise Linux 6OpenEXROut of support scope
Red Hat Enterprise Linux 7OpenEXRNot affected
Red Hat Enterprise Linux 8OpenEXRNot affected
Red Hat Enterprise Linux 9openexrAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2454127OpenEXR: OpenEXR: Memory corruption and Denial of Service via crafted EXR file processing

EPSS

Процентиль: 16%
0.00244
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.

CVSS3: 7.3
nvd
4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.

CVSS3: 7.3
debian
4 месяца назад

OpenEXR provides the specification and reference implementation of the ...

github
4 месяца назад

OpenEXR: integer overflow to OOB write in uncompress_b44_impl()

EPSS

Процентиль: 16%
0.00244
Низкий

6.6 Medium

CVSS3