Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-27622

Опубликовано: 03 мар. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.8

Описание

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.

РелизСтатусПримечание
devel

not-affected

3.4.6+ds-4
esm-apps/focal

released

2.3.0-6ubuntu0.5+esm2
esm-apps/jammy

released

2.5.7-1ubuntu0.1~esm2
esm-apps/noble

released

3.1.5-5.1ubuntu0.1~esm1
esm-apps/resolute

released

3.1.13-2ubuntu0.26.04.1~esm1
esm-infra-legacy/xenial

released

2.2.0-10ubuntu2.6+esm4
esm-infra/bionic

released

2.2.0-11.1ubuntu1.9+esm1
esm-infra/xenial

released

2.2.0-10ubuntu2.6+esm4
jammy

needed

noble

needed

Показывать по

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
5 месяцев назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.

CVSS3: 7.8
nvd
5 месяцев назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.

CVSS3: 7.8
debian
5 месяцев назад

OpenEXR provides the specification and reference implementation of the ...

suse-cvrf
4 месяца назад

Security update for openexr

rocky
3 месяца назад

Important: openexr security update

7.8 High

CVSS3