Description
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Published: 2026-08-25
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Read
Action: Immediate Patch
AI Analysis

Impact

An out-of-bounds read occurs in the SampleCountChannel::row() function of the OpenEXRUtil library when a deep image has a data window whose origin is non‑zero. The API is documented as 0‑based, but internally it offsets the base for absolute pixel coordinates; when dataWindow.min is non‑zero the computed address can point to memory outside the allocated sample‑count buffer. The resulting read can crash the application or, in a heap layout controlled by an attacker, leak adjacent heap memory to the caller. This vulnerability is limited to the read phase and does not grant code execution by itself but can expose sensitive data or enable denial‑of‑service attacks.

Affected Systems

The vulnerability affects the Academy Software Foundation's OpenEXR library in the following released versions: 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. Versions 3.2.11, 3.3.13, and 3.4.14 contain the fix and are not impacted.

Risk and Exploitability

With a CVSS score of 7.1, the vulnerability is considered high severity. The EPSS score is not available, but the lack of public exploitation evidence and the absence of KEV listing suggest a moderate likelihood of exploitation. Attackers must supply a malicious deep EXR file that contains a non‑zero data window origin; an application that opens such a file and calls SampleCountChannel::row() will experience the out‑of‑bounds read. The impact is confined to memory disclosure or crash, and exploitation requires the target application to use the affected API directly.

Generated by OpenCVE AI on August 25, 2026 at 21:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenEXR to a patched release (3.2.11 or newer, 3.3.13 or newer, or 3.4.14 or newer).
  • If an upgrade is not immediately possible, ensure that applications validate dataWindow.min before invoking SampleCountChannel::row(), or avoid processing deep EXR files with non‑zero dataWindow origins.
  • Review code that uses SampleCountChannel::row() to confirm it is only called with safe input; consider adding runtime checks or sanitization of the data window bounds.

Generated by OpenCVE AI on August 25, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Description OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Title OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-28T22:35:31.879Z

Reserved: 2026-07-07T19:41:00.004Z

Link: CVE-2026-59981

cve-icon Vulnrichment

Updated: 2026-08-28T22:35:26.693Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T20:16:58.907

Modified: 2026-09-09T21:07:31.353

Link: CVE-2026-59981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:45:03Z

Weaknesses