Impact
A heap out‑of‑bounds write occurs when the OpenEXR utility exrmetrics processes a crafted deep scanline EXR file. When pixel conversion options such as --pixelmode float or --bench are used, the tool expects FLOAT output while the underlying sample buffers are allocated with a HALF element size. The mismatch allows an attacker to write beyond the bounds of the allocated buffer, corrupting memory. This memory corruption could lead to execution of arbitrary code, result in a crash, or otherwise compromise the confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw affects OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, produced by the Academy Software Foundation. Version 3.3.13 and 3.4.14 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity vulnerability. EPSS data are unavailable and the flaw is not listed in the CISA KEV catalog, so current exploitation evidence is limited. The attack requires a crafted EXR file and the use of the risky pixelmode conversion options; it is therefore an input‑based vulnerability that can be triggered if exrmetrics processes untrusted data. While exploitation may presently be more difficult, the potential for arbitray code execution warrants prompt remediation.
OpenCVE Enrichment