Bug 2523187 (CVE-2026-59183) - CVE-2026-59183 openexr: OpenEXR: Integer Overflow Vulnerability Leading to Application Crash
Summary: CVE-2026-59183 openexr: OpenEXR: Integer Overflow Vulnerability Leading to Ap...
Keywords:
Status: NEW
Alias: CVE-2026-59183
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2523500 2523501 2523502
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-25 01:11 UTC by OSIDB Bzimport
Modified: 2026-08-25 14:54 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-25 01:11:47 UTC
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can overflow while decoding a crafted deep tiled EXR file, producing an invalid pointer that leads to a read from an unmapped memory address and a crash. Because the overflow occurs in the standard decoding path (exr_decoding_run), any application that decodes deep tiled EXR files is affected. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Note You need to log in before you can comment on or make changes to this bug.