CVE-2026-59183

EUVD-2026-65190
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can overflow while decoding a crafted deep tiled EXR file, producing an invalid pointer that leads to a read from an unmapped memory address and a crash. Because the overflow occurs in the standard decoding path (exr_decoding_run), any application that decodes deep tiled EXR files is affected. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 6.01%
Debian logo
Debian Releases
Debian Product
Codename
openexr
bookworm
vulnerable
forky
3.4.15+ds-1
fixed
sid
3.4.15+ds-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openexr
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
openexr
Amazon Linux 2023
0:3.1.5-1.amzn2023.0.12
fixed
openexr-debuginfo
Amazon Linux 2023
0:3.1.5-1.amzn2023.0.12
fixed
openexr-debugsource
Amazon Linux 2023
0:3.1.5-1.amzn2023.0.12
fixed
openexr-devel
Amazon Linux 2023
0:3.1.5-1.amzn2023.0.12
fixed
openexr-libs
Amazon Linux 2023
0:3.1.5-1.amzn2023.0.12
fixed
openexr-libs-debuginfo
Amazon Linux 2023
0:3.1.5-1.amzn2023.0.12
fixed