Executive brief
OpenEXR is a widely-used image format library in the motion picture and visual effects industries. A NULL pointer dereference in the OpenEXRCore C API allows an attacker to crash applications that process untrusted EXR files, causing a denial of service. Versions 3.4.0 through 3.4.12 are affected; version 3.4.13 contains the fix.
Technical details
The vulnerability is a NULL pointer dereference in the exr_attr_set_bytes() function in OpenEXRCore. The public setter validates the top-level exr_attr_bytes_t pointer but fails to verify that the nested type_hint pointer is non-NULL when hint_length is greater than zero. When exr_attr_bytes_create() attempts to memcpy from a NULL type_hint with a positive hint_length, it triggers a segmentation fault. The flaw is reachable directly through the public OpenEXRCore C API with no authentication required and results in a deterministic crash. The vulnerability is fixed in version 3.4.13.
Affected products
- Academy Software Foundation OpenEXR 3.4.0 through 3.4.12
Timeline
- 2026-06-23: disclosed: GitHub security advisory published
- 2026-08-25: patched: Fixed in version 3.4.13