Bug 2523654 (CVE-2026-59184)

Summary: CVE-2026-59184 OpenEXR: OpenEXR: Out-of-bounds write vulnerability via crafted EXR files
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in OpenEXR. A remote attacker could exploit this vulnerability by providing a specially crafted EXR image file with a nonzero dataWindow.min. This could cause the `TypedFlatImageChannel::row()` function to return an invalid memory pointer, leading to out-of-bounds or use-after-free writes when an application processes the image using `FlatHalfChannel::row()`. This could result in arbitrary code execution or a denial of service (DoS) in affected applications that process untrusted EXR files.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2537140, 2537141, 2537142    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-25 16:46:39 UTC
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.