OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:7678 https://access.redhat.com/errata/RHSA-2026:7678
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:7682 https://access.redhat.com/errata/RHSA-2026:7682
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:8869 https://access.redhat.com/errata/RHSA-2026:8869
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8863 https://access.redhat.com/errata/RHSA-2026:8863
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:8871 https://access.redhat.com/errata/RHSA-2026:8871
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:8870 https://access.redhat.com/errata/RHSA-2026:8870
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8888 https://access.redhat.com/errata/RHSA-2026:8888
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:8872 https://access.redhat.com/errata/RHSA-2026:8872
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:12340 https://access.redhat.com/errata/RHSA-2026:12340
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:12341 https://access.redhat.com/errata/RHSA-2026:12341
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:12339 https://access.redhat.com/errata/RHSA-2026:12339
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:12338 https://access.redhat.com/errata/RHSA-2026:12338