CVE-2026-54920 | CVSS: 0 | 严重级别: NONE
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta par
参考链接:
• https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-fp
• https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-fp
📌 数据来源: NVD 官方