Bug 2523655 (CVE-2026-59186) - CVE-2026-59186 OpenEXR: OpenEXR: Heap out-of-bounds write via crafted tiled EXR file
Summary: CVE-2026-59186 OpenEXR: OpenEXR: Heap out-of-bounds write via crafted tiled E...
Keywords:
Status: NEW
Alias: CVE-2026-59186
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2537154 2537155 2537156
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-25 16:46 UTC by OSIDB Bzimport
Modified: 2026-09-19 12:02 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-25 16:46:43 UTC
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.


Note You need to log in before you can comment on or make changes to this bug.