CVE-2021-26945 PUBLISHED

An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.

EPSS 0.26% · 48.8th percentile

Risk Scores

EPSS Score
0.26%
48.8th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSopenexr0, 3.1.5-5.1, 3.1.5-5.1build1
Ubuntu:Pro:20.04:LTSopenexr2.3.0-6build1, 2.3.0-6, 2.3.0-6ubuntu0.1
Ubuntu:25.10openexr3.1.13-2, 0
Ubuntu:Pro:22.04:LTSopenexr0, 2.5.4-2, 2.5.7-1

Timeline

References

Open in Interactive Console →