Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41142

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

A flaw was found in OpenEXR, an image storage format library for the motion picture industry. An integer overflow vulnerability exists in the ImageChannel::resize function, which can be triggered when processing a specially crafted OpenEXR image file through the OpenEXRUtil public API. This can lead to a heap out-of-bounds write, potentially allowing a remote attacker to achieve arbitrary code execution, disclose sensitive information, or cause a denial of service.

Отчет

This is an Important vulnerability in OpenEXR, which could lead to arbitrary code execution, sensitive information disclosure, or denial of service. The flaw, an integer overflow in the ImageChannel::resize function, is triggered when an application processes a specially crafted OpenEXR image file. Successful exploitation requires user interaction, such as opening a malicious file.

Меры по смягчению последствий

To mitigate this vulnerability, users should avoid processing or opening OpenEXR image files from untrusted or unknown sources. Restricting the input of OpenEXR files to only trusted origins can reduce the risk of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6OpenEXRNot affected
Red Hat Enterprise Linux 7OpenEXRNot affected
Red Hat Enterprise Linux 8OpenEXRNot affected
Red Hat Enterprise Linux 10openexrFixedRHSA-2026:3849913.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportopenexrFixedRHSA-2026:3902413.07.2026
Red Hat Enterprise Linux 9openexrFixedRHSA-2026:3849813.07.2026
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsopenexrFixedRHSA-2026:3902713.07.2026
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsopenexrFixedRHSA-2026:3902613.07.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportopenexrFixedRHSA-2026:3902513.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2467623OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing

EPSS

Процентиль: 28%
0.00355
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

CVSS3: 8.8
nvd
3 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

CVSS3: 8.8
debian
3 месяца назад

OpenEXR provides the specification and reference implementation of the ...

suse-cvrf
2 месяца назад

Security update for openexr

rocky
17 дней назад

Important: openexr security update

EPSS

Процентиль: 28%
0.00355
Низкий

8.8 High

CVSS3