Executive brief
OpenEXR is a widely used professional image format for high-quality visual effects and motion pictures. A flaw in how the library handles image resizing could allow a specially crafted image file to crash an application or potentially allow an attacker to execute unauthorized code. This affects software that processes these images, such as video editors, 3D rendering tools, and thumbnail generators, potentially leading to data theft or system compromise if a user opens a malicious file.
Technical details
An integer overflow exists in Imf::ImageChannel::resize() within src/lib/OpenEXRUtil/ImfImageChannel.cpp. The vulnerability occurs when calculating the total number of pixels (_numPixels) by multiplying _pixelsPerRow and _pixelsPerColumn using signed 32-bit integer arithmetic before widening to size_t. If the product exceeds INT_MAX, the resulting value wraps, leading to an undersized heap allocation in TypedFlatImageChannel or TypedDeepImageChannel. Subsequent write operations use the original, un-truncated dimensions as a stride, resulting in a heap-based out-of-bounds (OOB) write. Attackers can exploit this via the public API or by providing a malicious EXR file to applications using the OpenEXRUtil abstraction. The issue is patched in versions 3.2.9, 3.3.11, and 3.4.11.
Affected products
- AcademySoftwareFoundation openexr >= 3.0.0, < 3.2.9
- AcademySoftwareFoundation openexr >= 3.3.0, < 3.3.11
- AcademySoftwareFoundation openexr >= 3.4.0, < 3.4.11
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
Timeline
- 2026-04-17: disclosed: Initial report/PR submitted to GitHub
- 2026-04-22: patched: Fix merged into main branch
- 2026-05-05: advisory: GitHub Security Advisory published
- 2026-05-07: advisory: NVD publication date
References
- https://github.com/AcademySoftwareFoundation/openexr/commit/0592ee539f33c122c90f09238579b902d838afb4
- https://github.com/AcademySoftwareFoundation/openexr/pull/2367
- https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m25w-72cj-q6mg
- https://access.redhat.com/security/cve/CVE-2026-41142
- https://bugzilla.redhat.com/show_bug.cgi?id=2467623
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41142.json