CVE-2026-41142

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*

History

08 May 2026, 17:00

Type Values Removed Values Added
CPE cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
First Time Openexr
Openexr openexr
References () https://github.com/AcademySoftwareFoundation/openexr/commit/0592ee539f33c122c90f09238579b902d838afb4 - () https://github.com/AcademySoftwareFoundation/openexr/commit/0592ee539f33c122c90f09238579b902d838afb4 - Patch
References () https://github.com/AcademySoftwareFoundation/openexr/pull/2367 - () https://github.com/AcademySoftwareFoundation/openexr/pull/2367 - Issue Tracking, Patch
References () https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m25w-72cj-q6mg - () https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m25w-72cj-q6mg - Exploit, Vendor Advisory

07 May 2026, 15:03

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 04:16

Updated : 2026-05-08 17:00


NVD link : CVE-2026-41142

Mitre link : CVE-2026-41142

CVE.ORG link : CVE-2026-41142


JSON object : View

Products Affected

openexr

  • openexr
CWE
CWE-190

Integer Overflow or Wraparound