Junglewise Threat Intelligence

CVE-2026-59187: OpenEXR heap buffer overflow in exrmetrics deep scanline processing

CVE-2026-59187 · Severity: high · CVSS 7.1 · Published 2026-08-25

Technologies: Academy Software Foundation OpenEXR. Vendors: Academy Software Foundation.

Executive brief

OpenEXR is a widely-used image format library for motion picture and visual effects production. A heap buffer overflow vulnerability in the exrmetrics tool can be triggered when processing specially-crafted deep scanline EXR images with pixel conversion options, potentially allowing an attacker to crash the application or execute arbitrary code.

Technical details

The vulnerability is a heap out-of-bounds write in the exrmetrics utility when processing deep scanline EXR files with pixel mode conversion options (--pixelmode float or --bench). The root cause is a type mismatch: when pixel mode conversion is requested, the output header channels are converted to FLOAT (4 bytes), but the backing sample data buffers are allocated based on the input header's channel types (e.g., HALF at 2 bytes). This causes readPixels() to write 4-byte FLOAT values into 2-byte buffers, resulting in heap corruption. The vulnerability requires user interaction (opening a crafted EXR file with exrmetrics using specific flags). The issue is fixed in OpenEXR 3.3.13 and 3.4.14 by allocating sample data buffers using the output header's channel types.

Affected products

  • Academy Software Foundation OpenEXR 3.3.0 through 3.3.12, 3.4.0 through 3.4.13

Timeline

  • 2026-08-25: disclosed
  • 2026: patched: Fixed in versions 3.3.13 and 3.4.14

References