Junglewise Threat Intelligence

CVE-2026-44663: AcademySoftwareFoundation OpenEXR integer overflow in HTJ2K decoder

CVE-2026-44663 · Severity: medium · CVSS 6.1 · Published 2026-06-18

Technologies: AcademySoftwareFoundation OpenEXR.

Executive brief

OpenEXR is a standard library used in the motion picture industry for handling high-quality image files. A vulnerability in its image decoding component allows a specially crafted image file to cause a memory error. If a user opens such a file, it could lead to an application crash or potentially allow an attacker to gain unauthorized control over the system.

Technical details

An integer overflow exists in the ht_undo_impl() function within src/lib/OpenEXRCore/internal_ht.cpp. The vulnerability is caused by 32-bit signed arithmetic when multiplying a channel's width (int32_t) by its bytes_per_element. When processing FLOAT data with widths exceeding 536,870,912, the resulting product overflows INT32_MAX, leading to a corrupted offset used in pointer arithmetic. This results in a heap-based out-of-bounds write during the decompression of HTJ2K-compressed EXR files. The issue is present in three distinct paths within the HTJ2K decoder: raster line offset calculation, bytes-per-line accumulation, and pixel-line pointer advancement. The vulnerability has been addressed in version 3.4.12 by casting operands to 64-bit integers before multiplication.

Affected products

  • AcademySoftwareFoundation OpenEXR 3.4.0 through 3.4.11

Timeline

  • 2026-05-25: patched: Fixed in version 3.4.12
  • 2026-05-25: advisory: GitHub Security Advisory GHSA-777r-f9x8-7r84 published
  • 2026-06-18: disclosed: CVE-2026-44663 published to NVD

References