[CVE-2026-59183] OpenEXR is the reference implementation and specification fo

CVE-2026-59183 | CVSS: 5.5 | 严重级别: MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can overflow while decoding a crafted deep tiled EXR file, producing an invalid pointer that leads to a read from an unmapped memory address and a crash. Because the overflow occurs in the standard decoding path (exr_decoding_run), any application that decodes deep tiled EXR files is affected. This issue is fixed in version

参考链接:
https://github.com/AcademySoftwareFoundation/openexr/commit/5e55a64ad1f119a81665
https://github.com/AcademySoftwareFoundation/openexr/commit/a6cf183725b5665ac3fd
https://github.com/AcademySoftwareFoundation/openexr/commit/e2adb5be3bbc3a1f82f2

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部