Junglewise Threat Intelligence

CVE-2026-41142: AcademySoftwareFoundation OpenEXR heap OOB write in ImageChannel::resize

CVE-2026-41142 · Severity: high · CVSS 8.8 · Published 2026-05-07

Technologies: AcademySoftwareFoundation OpenEXR, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10. Vendors: Red Hat.

Executive brief

OpenEXR is a widely used professional image format for high-quality visual effects and motion pictures. A flaw in how the library handles image resizing could allow a specially crafted image file to crash an application or potentially allow an attacker to execute unauthorized code. This affects software that processes these images, such as video editors, 3D rendering tools, and thumbnail generators, potentially leading to data theft or system compromise if a user opens a malicious file.

Technical details

An integer overflow exists in Imf::ImageChannel::resize() within src/lib/OpenEXRUtil/ImfImageChannel.cpp. The vulnerability occurs when calculating the total number of pixels (_numPixels) by multiplying _pixelsPerRow and _pixelsPerColumn using signed 32-bit integer arithmetic before widening to size_t. If the product exceeds INT_MAX, the resulting value wraps, leading to an undersized heap allocation in TypedFlatImageChannel or TypedDeepImageChannel. Subsequent write operations use the original, un-truncated dimensions as a stride, resulting in a heap-based out-of-bounds (OOB) write. Attackers can exploit this via the public API or by providing a malicious EXR file to applications using the OpenEXRUtil abstraction. The issue is patched in versions 3.2.9, 3.3.11, and 3.4.11.

Affected products

  • AcademySoftwareFoundation openexr >= 3.0.0, < 3.2.9
  • AcademySoftwareFoundation openexr >= 3.3.0, < 3.3.11
  • AcademySoftwareFoundation openexr >= 3.4.0, < 3.4.11
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Enterprise Linux 10

Timeline

  • 2026-04-17: disclosed: Initial report/PR submitted to GitHub
  • 2026-04-22: patched: Fix merged into main branch
  • 2026-05-05: advisory: GitHub Security Advisory published
  • 2026-05-07: advisory: NVD publication date

References

Related threats