Количество 13
Количество 13
CVE-2026-34588
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.
CVE-2026-34588
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.
CVE-2026-34588
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.
CVE-2026-34588
OpenEXR provides the specification and reference implementation of the ...
RLSA-2026:19359
Important: openexr security update
RLSA-2026:19146
Important: openexr security update
RLSA-2026:15888
Important: openexr security update
RLSA-2026:15887
Important: openexr security update
GHSA-588r-cr5c-w6hf
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
ELSA-2026-19359
ELSA-2026-19359: openexr security update (IMPORTANT)
ELSA-2026-15888
ELSA-2026-15888: openexr security update (IMPORTANT)
ELSA-2026-15887
ELSA-2026-15887: openexr security update (IMPORTANT)
openSUSE-SU-2026:20605-1
Security update for openexr
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-34588 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-34588 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-34588 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-34588 OpenEXR provides the specification and reference implementation of the ... | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
RLSA-2026:19359 Important: openexr security update | 0% Низкий | 2 месяца назад | ||
RLSA-2026:19146 Important: openexr security update | 0% Низкий | 2 месяца назад | ||
RLSA-2026:15888 Important: openexr security update | 0% Низкий | 3 месяца назад | ||
RLSA-2026:15887 Important: openexr security update | 0% Низкий | 3 месяца назад | ||
GHSA-588r-cr5c-w6hf OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
ELSA-2026-19359 ELSA-2026-19359: openexr security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-15888 ELSA-2026-15888: openexr security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-15887 ELSA-2026-15887: openexr security update (IMPORTANT) | 3 месяца назад | |||
openSUSE-SU-2026:20605-1 Security update for openexr | 3 месяца назад |
Уязвимостей на страницу