Executive brief
OpenEXR is a widely used industry-standard library for handling high-quality image files in the motion picture and visual effects industry. A vulnerability in how the library processes certain compressed image files could allow an attacker to crash applications or potentially execute malicious code if a user opens a specially crafted, oversized image. This could lead to data theft, system compromise, or service disruptions for studios and artists using affected software.
Technical details
An integer overflow vulnerability exists in `internal_dwa_compressor.h` within the `setupChannelData` function. The flaw occurs because the library performs `curc->width * curc->height` using 32-bit integer arithmetic without proper casting to `size_t`. When processing images with dimensions that exceed the `INT32_MAX` limit, the multiplication wraps around, resulting in an incorrect pointer offset for `planarUncRle`. This causes subsequent RLE decoding operations to write data to unintended heap locations. The vulnerability specifically affects non-DCT channels (such as UINT or single-channel layouts) using DWA compression. Patches are available in versions 3.2.8, 3.3.10, and 3.4.10.
Affected products
- AcademySoftwareFoundation OpenEXR 3.2.0-3.2.7, 3.3.0-3.3.9, 3.4.0-3.4.9
Timeline
- 2026-04-17: patched: Versions 3.2.8, 3.3.10, and 3.4.10 released
- 2026-04-18: advisory: GitHub Security Advisory published
- 2026-04-21: disclosed: CVE-2026-40244 published
References
- https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.8
- https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.10
- https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.10
- https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-j526-66f6-fxhx
- https://access.redhat.com/security/cve/CVE-2026-40244
- https://bugzilla.redhat.com/show_bug.cgi?id=2459955
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40244.json