Junglewise Threat Intelligence

CVE-2026-40244: OpenEXR integer overflow in DWA compressor

CVE-2026-40244 · Severity: high · CVSS 7.1 · Published 2026-04-21

Technologies: AcademySoftwareFoundation OpenEXR.

Executive brief

OpenEXR is a widely used industry-standard library for handling high-quality image files in the motion picture and visual effects industry. A vulnerability in how the library processes certain compressed image files could allow an attacker to crash applications or potentially execute malicious code if a user opens a specially crafted, oversized image. This could lead to data theft, system compromise, or service disruptions for studios and artists using affected software.

Technical details

An integer overflow vulnerability exists in `internal_dwa_compressor.h` within the `setupChannelData` function. The flaw occurs because the library performs `curc->width * curc->height` using 32-bit integer arithmetic without proper casting to `size_t`. When processing images with dimensions that exceed the `INT32_MAX` limit, the multiplication wraps around, resulting in an incorrect pointer offset for `planarUncRle`. This causes subsequent RLE decoding operations to write data to unintended heap locations. The vulnerability specifically affects non-DCT channels (such as UINT or single-channel layouts) using DWA compression. Patches are available in versions 3.2.8, 3.3.10, and 3.4.10.

Affected products

  • AcademySoftwareFoundation OpenEXR 3.2.0-3.2.7, 3.3.0-3.3.9, 3.4.0-3.4.9

Timeline

  • 2026-04-17: patched: Versions 3.2.8, 3.3.10, and 3.4.10 released
  • 2026-04-18: advisory: GitHub Security Advisory published
  • 2026-04-21: disclosed: CVE-2026-40244 published

References