Bug 2523654 (CVE-2026-59184) - CVE-2026-59184 OpenEXR: OpenEXR: Out-of-bounds write vulnerability via crafted EXR files
Summary: CVE-2026-59184 OpenEXR: OpenEXR: Out-of-bounds write vulnerability via crafte...
Keywords:
Status: NEW
Alias: CVE-2026-59184
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2537140 2537141 2537142
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-25 16:46 UTC by OSIDB Bzimport
Modified: 2026-09-19 11:24 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-25 16:46:39 UTC
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Note You need to log in before you can comment on or make changes to this bug.