Junglewise Threat Intelligence

CVE-2026-34588: OpenEXR integer overflow in PIZ decoder leads to OOB read and write

CVE-2026-34588 · Severity: high · CVSS 7.8 · Published 2026-04-06

Technologies: Red Hat Enterprise Linux AppStream, AcademySoftwareFoundation OpenEXR. Vendors: Red Hat, PyPI.

Executive brief

OpenEXR is a widely used industry-standard library for processing high-quality image files in the motion picture and visual effects industry. A security flaw in how the library handles specific image compression (PIZ) could allow a malicious image file to corrupt memory when opened. This could lead to application crashes, unauthorized data access, or potentially allow an attacker to execute malicious code on the affected system.

Technical details

An integer overflow vulnerability exists in the 'internal_exr_undo_piz()' function within OpenEXR's PIZ decoder. The root cause is the use of signed 32-bit arithmetic when advancing the working wavelet pointer ('wavbuf += nx * ny * wcount'). Because the variables 'nx', 'ny', and 'wcount' are integers, a crafted EXR file can cause the product to overflow and wrap, leading the decoder to operate on an incorrect memory address. Since the wavelet decode path operates in-place, this results in both out-of-bounds (OOB) reads and OOB writes. The vulnerability is fixed in versions 3.2.7, 3.3.9, and 3.4.9.

Affected products

  • AcademySoftwareFoundation OpenEXR 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9
  • Red Hat Red Hat Enterprise Linux AppStream 9, 10

Timeline

  • 2026-04-03: patched: OpenEXR versions 3.2.7, 3.3.9, and 3.4.9 released
  • 2026-04-05: advisory: GitHub Security Advisory GHSA-588r-cr5c-w6hf published
  • 2026-04-06: disclosed: CVE-2026-34588 published to NVD

References

Related threats