Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. | |
| Title | OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write | |
| Weaknesses | CWE-416 CWE-787 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T19:20:34.302Z
Reserved: 2026-07-02T19:53:48.830Z
Link: CVE-2026-59184
No data.
Status : Received
Published: 2026-08-25T17:17:36.603
Modified: 2026-08-25T17:17:36.603
Link: CVE-2026-59184
No data.
OpenCVE Enrichment
Updated: 2026-08-25T19:30:05Z