Executive brief
OpenEXR is a standard library used in the motion picture industry for handling high-quality image files. A vulnerability in its image decoding component allows a specially crafted image file to cause a memory error. If a user opens such a file, it could lead to an application crash or potentially allow an attacker to gain unauthorized control over the system.
Technical details
An integer overflow exists in the ht_undo_impl() function within src/lib/OpenEXRCore/internal_ht.cpp. The vulnerability is caused by 32-bit signed arithmetic when multiplying a channel's width (int32_t) by its bytes_per_element. When processing FLOAT data with widths exceeding 536,870,912, the resulting product overflows INT32_MAX, leading to a corrupted offset used in pointer arithmetic. This results in a heap-based out-of-bounds write during the decompression of HTJ2K-compressed EXR files. The issue is present in three distinct paths within the HTJ2K decoder: raster line offset calculation, bytes-per-line accumulation, and pixel-line pointer advancement. The vulnerability has been addressed in version 3.4.12 by casting operands to 64-bit integers before multiplication.
Affected products
- AcademySoftwareFoundation OpenEXR 3.4.0 through 3.4.11
Timeline
- 2026-05-25: patched: Fixed in version 3.4.12
- 2026-05-25: advisory: GitHub Security Advisory GHSA-777r-f9x8-7r84 published
- 2026-06-18: disclosed: CVE-2026-44663 published to NVD