← Zuruck zu CVEs
CVE-2026-40250
HIGH7.1
Beschreibung
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan->width * chan->bytes_per_element` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1040`.
CVE Details
CVSS v3.1 Bewertung7.1
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht4/21/2026
Zuletzt geandert4/22/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
openexr:openexr
Schwachen (CWE)
CWE-190
Referenzen
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.8(security-advisories@github.com)
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.10(security-advisories@github.com)
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.10(security-advisories@github.com)
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m5qw-23x2-6phj(security-advisories@github.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.