OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1722` performs `curc->width * curc->height` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other locations by the recent CVE-2026-34589 batch, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1722`.
References
Configurations
Configuration 1 (hide)
|
History
30 Jun 2026, 03:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
22 Apr 2026, 18:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.8 - Product, Release Notes | |
| References | () https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.10 - Product, Release Notes | |
| References | () https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.10 - Product, Release Notes | |
| References | () https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-j526-66f6-fxhx - Mitigation, Vendor Advisory | |
| CPE | cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* | |
| First Time |
Openexr
Openexr openexr |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
21 Apr 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 02:16
Updated : 2026-07-15 02:21
NVD link : CVE-2026-40244
Mitre link : CVE-2026-40244
CVE.ORG link : CVE-2026-40244
JSON object : View
Products Affected
openexr
- openexr
CWE
CWE-190
Integer Overflow or Wraparound
