Executive brief
OpenEXR is the industry-standard format for high-quality images used in motion pictures and visual effects. A vulnerability in the HTJ2K decoder allows attackers to read memory beyond the allocated buffer by crafting a malicious EXR file with an oversized header-length field. This could lead to information disclosure or application crashes during normal image processing workflows.
Technical details
The vulnerability is an out-of-bounds read in the HTJ2K decoder (versions 3.4.0–3.4.12) caused by insufficient validation of the PLEN (header-length) field parsed from compressed chunk data. The decoder reads an attacker-controlled PLEN value without verifying it fits within the available buffer, then advances the codestream pointer by this unvalidated amount. This causes the pointer to exceed the buffer boundary, which is passed to the OpenJPH memory-input decoder, triggering an out-of-bounds read. The attack is reachable during normal decoding of an untrusted EXR file without requiring authentication or special privileges. A fix was introduced in version 3.4.13 that validates the header length before using it.
Affected products
- Academy Software Foundation OpenEXR 3.4.0 through 3.4.12
Timeline
- 2026-08-25: disclosed
- 2026-06-12: patched: Fixed in version 3.4.13, released 2026-06-19