Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40250

Опубликовано: 21 апр. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, internal_dwa_compressor.h:1040 performs chan->width * chan->bytes_per_element in int32 arithmetic without a (size_t) cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses internal_dwa_compressor.h:1040.

A flaw was found in OpenEXR, a library for the EXR image file format. An integer overflow vulnerability exists in the internal_dwa_compressor.h component during the calculation of image channel dimensions. This issue, caused by insufficient handling of int32 arithmetic, could allow a local attacker to cause memory corruption by enticing a user to open a specially crafted EXR file. This may lead to a denial of service or potentially more severe impacts.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening or processing untrusted EXR image files. If processing EXR files is necessary, ensure they originate from trusted sources. This operational control reduces the risk of a local attacker exploiting the integer overflow vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10openexrFix deferred
Red Hat Enterprise Linux 6OpenEXRFix deferred
Red Hat Enterprise Linux 7OpenEXRFix deferred
Red Hat Enterprise Linux 8OpenEXRFix deferred
Red Hat Enterprise Linux 9openexrFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2459962OpenEXR: OpenEXR: Integer overflow leads to memory corruption and denial of service

EPSS

Процентиль: 37%
0.0045
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan->width * chan->bytes_per_element` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1040`.

CVSS3: 7.1
nvd
4 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan->width * chan->bytes_per_element` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1040`.

CVSS3: 7.1
debian
4 месяца назад

OpenEXR provides the specification and reference implementation of the ...

suse-cvrf
3 месяца назад

Security update for openexr

suse-cvrf
3 месяца назад

Security update for openexr

EPSS

Процентиль: 37%
0.0045
Низкий

6.8 Medium

CVSS3