Junglewise Threat Intelligence

CVE-2026-68515: OpenEXR exrmultiview heap buffer overflow

CVE-2026-68515 · Severity: high · CVSS 7.1 · Published 2026-08-25

Technologies: Academy Software Foundation OpenEXR. Vendors: Academy Software Foundation.

Executive brief

OpenEXR is a widely-used image format standard for motion pictures. The exrmultiview utility, which combines multiple EXR image files, contains a heap buffer overflow vulnerability when processing specially crafted input files with misaligned channel subsampling. An attacker can trigger this flaw with normal command-line usage, potentially causing memory corruption, service disruption, or code execution.

Technical details

This is a heap out-of-bounds write vulnerability in the exrmultiview utility. The root cause is insufficient validation of the combined data window against individual input file channel subsampling factors before allocating and writing to pixel buffers. When two valid EXR files are combined via exrmultiview, their union dataWindow may not be aligned to one view's channel subsampling; the utility truncates the calculated buffer size but then writes beyond it via a Slice operation. The attack requires no authentication or special privileges—normal invocation (e.g., exrmultiview left.exr right.exr out.exr) with attacker-controlled input files triggers the flaw. The fix validates the combined window against subsampling constraints and rejects misaligned inputs. Patches are available in versions 3.2.11, 3.3.13, and 3.4.14.

Affected products

  • Academy Software Foundation OpenEXR before 3.2.11, 3.3.0 through 3.3.12, 3.4.0 through 3.4.13

Timeline

  • 2026-08-25: disclosed
  • 2026: patched: Fixed in versions 3.2.11, 3.3.13, and 3.4.14

References