CVE-2026-41142
EUVD-2026-2825107.05.2026, 04:16
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openexr | openexr | 3.0.0 ≤ 𝑥 < 3.2.9 |
| openexr | openexr | 3.3.0 ≤ 𝑥 < 3.3.11 |
| openexr | openexr | 3.4.0 ≤ 𝑥 < 3.4.11 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.1.10-8.el10_2.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:3.1.10-8.el10_0.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:3.1.1-3.el9_8.3 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:3.1.1-2.el9_2.4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:3.1.1-2.el9_4.4 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:3.1.1-3.el9_6.3 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libIlmImf-2_2-23 |
| ||||||||||||||||||
| libIlmImfUtil-2_2-23 |
| ||||||||||||||||||
| openexr-devel |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| openexr |
| ||
| openexr-debuginfo |
| ||
| openexr-debugsource |
| ||
| openexr-devel |
| ||
| openexr-libs |
| ||
| openexr-libs-debuginfo |
|