CRITICAL🇵🇱 Wersja polska

CVE-2023-5841

CVSS 9.1v3.1pub. 2024-02-01upd. 2025-11-04

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

🤖 AI Analysis
How it works

The vulnerability results from improper validation of the scanline samples count in OpenEXR files containing deep scanline data. When an application processes a specially crafted image file, an incorrect sample count value leads to data being written outside the allocated heap buffer. This is a classic CWE-122/CWE-787 error — heap buffer overflow with the possibility of overwriting adjacent memory areas.

Impact

An attacker can cause memory corruption in the process handling the file, which could result in disclosure of sensitive data or arbitrary code execution (RCE) in the application context. The network vector without authentication requirements significantly increases the risk of vulnerability exploitation.

Mitigation & patch

Update the OpenEXR library to version 3.2.2 or newer (in the 3.2.x branch) or to version 3.1.12 or newer (in the 3.1.x branch). Linux distribution users should apply available system package updates. Until the patch is deployed, it is recommended to avoid processing OpenEXR files from untrusted sources.

Who is affected

Academy Software Foundation OpenEXR in versions 3.2.1 and earlier, and in the 3.1.x branch earlier than 3.1.12.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Openexr

    APP
    Openexr
    ≤ 3.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-45696HIGH8.3same product

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion ...

CVE-2026-41142HIGH8.8same product

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...

CVE-2026-42216HIGH8.8same product

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...

CVE-2026-40244HIGH8.4same product

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...

CVE-2026-40250HIGH8.4same product

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...