HIGH🇵🇱 Wersja polska

CVE-2026-40244

CVSS 8.4v4.0pub. 2026-04-21upd. 2026-06-30

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1722` performs `curc->width * curc->height` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other locations by the recent CVE-2026-34589 batch, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1722`.

CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openexr

    APP
    Openexr
    3.2.0 – 3.2.8 (excl.)3.3.0 – 3.3.10 (excl.)3.4.0 – 3.4.10 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-5841CRITICAL9.1PL ✓same product

Heap-based buffer overflow w bibliotece OpenEXR przy parsowaniu deep scanline

CVE-2026-45696HIGH8.3same product

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion ...

CVE-2026-42216HIGH8.8same product

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...

CVE-2026-41142HIGH8.8same product

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...

CVE-2026-40250HIGH8.4same product

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage forma...