Junglewise Threat Intelligence

CVE-2026-55371: OpenEXR NULL pointer dereference in exr_attr_set_bytes()

CVE-2026-55371 · Severity: info · Published 2026-08-25

Technologies: Academy Software Foundation OpenEXR. Vendors: Academy Software Foundation.

Executive brief

OpenEXR is a widely-used image format library in the motion picture and visual effects industries. A NULL pointer dereference in the OpenEXRCore C API allows an attacker to crash applications that process untrusted EXR files, causing a denial of service. Versions 3.4.0 through 3.4.12 are affected; version 3.4.13 contains the fix.

Technical details

The vulnerability is a NULL pointer dereference in the exr_attr_set_bytes() function in OpenEXRCore. The public setter validates the top-level exr_attr_bytes_t pointer but fails to verify that the nested type_hint pointer is non-NULL when hint_length is greater than zero. When exr_attr_bytes_create() attempts to memcpy from a NULL type_hint with a positive hint_length, it triggers a segmentation fault. The flaw is reachable directly through the public OpenEXRCore C API with no authentication required and results in a deterministic crash. The vulnerability is fixed in version 3.4.13.

Affected products

  • Academy Software Foundation OpenEXR 3.4.0 through 3.4.12

Timeline

  • 2026-06-23: disclosed: GitHub security advisory published
  • 2026-08-25: patched: Fixed in version 3.4.13

References