Junglewise Threat Intelligence

CVE-2026-68516: OpenEXR stack out-of-bounds write in HTJ2K decoding

CVE-2026-68516 · Severity: medium · CVSS 6.5 · Published 2026-08-24

Technologies: Academy Software Foundation OpenEXR. Vendors: Academy Software Foundation.

Executive brief

OpenEXR is a widely-used image format for motion pictures and professional visual effects. A crafted EXR file with specific JPEG 2000 compression settings can cause OpenEXR to crash during decoding, disrupting workflows and potentially being weaponized in media processing pipelines or automated systems that handle untrusted image files.

Technical details

This vulnerability is a stack out-of-bounds write triggered by malformed HTJ2K-compressed EXR files. The root cause lies in the vendored OpenJPH AVX2 decoder: when JPEG 2000 SIZ fields position the first tile outside the visible image boundaries, invalid tile and codeblock geometry calculations lead to out-of-bounds stack writes. OpenEXR validates decoded codestream dimensions against chunk size but does not reject geometric configurations where the first tile does not intersect the image. The attack vector is local (file processing); no network or authentication bypass is required. An attacker can trigger denial of service by crafting a malicious EXR file. The vulnerability affects versions 3.4.0 through 3.4.13 and is fixed in 3.4.14 via an update to OpenJPH 0.31.0.

Affected products

  • Academy Software Foundation OpenEXR 3.4.0 through 3.4.13

Timeline

  • 2026-08-24: disclosed
  • 2026-08-16: patched: Version 3.4.14 released with OpenJPH 0.31.0 update

References