Bug 2523172 (CVE-2026-53532)
| Summary: | CVE-2026-53532 OpenEXR: OpenEXR: Denial of Service via crafted HTJ2K-compressed EXR file | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in OpenEXR. A remote attacker can provide a specially crafted HTJ2K-compressed EXR file, which causes an unconditional process abort in applications that process untrusted input. This denial of service occurs because OpenEXR passes a malformed QCD marker to the vendored OpenJPH library, triggering an assertion that cannot be gracefully handled. This vulnerability can lead to the unavailability of services using OpenEXR to process image files.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-24 22:31:24 UTC
|