OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1722` performs `curc->width * curc->height` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other locations by the recent CVE-2026-34589 batch, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1722`.
References
| Link | Resource |
|---|---|
| https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.8 | Product Release Notes |
| https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.10 | Product Release Notes |
| https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.10 | Product Release Notes |
| https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-j526-66f6-fxhx | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Apr 2026, 18:41
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* | |
| First Time |
Openexr
Openexr openexr |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
| References | () https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.8 - Product, Release Notes | |
| References | () https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.10 - Product, Release Notes | |
| References | () https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.10 - Product, Release Notes | |
| References | () https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-j526-66f6-fxhx - Mitigation, Vendor Advisory |
21 Apr 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 02:16
Updated : 2026-04-22 18:41
NVD link : CVE-2026-40244
Mitre link : CVE-2026-40244
CVE.ORG link : CVE-2026-40244
JSON object : View
Products Affected
openexr
- openexr
CWE
CWE-190
Integer Overflow or Wraparound
