Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. | |
| Title | OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write | |
| Weaknesses | CWE-416 CWE-787 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T19:20:34.302Z
Reserved: 2026-07-02T19:53:48.830Z
Link: CVE-2026-59184
Updated: 2026-08-25T18:33:42.401Z
Status : Received
Published: 2026-08-25T17:17:36.603
Modified: 2026-08-25T20:16:58.080
Link: CVE-2026-59184
No data.
OpenCVE Enrichment
Updated: 2026-08-25T19:30:05Z