VDB
CVE-2026-59983
CVE-2026-59983
PUBLISHED
CVSS 5.5 MEDIUM
Reported by GitHub_M · Published August 25, 2026
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds read. The vulnerability is reached when a crafted uncompressed deep-tile EXR causes the sample-count table size calculation in OpenEXRCore decoding.c to wrap before unpack_sample_table() iterates over the full attacker-controlled tile dimensions, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AcademySoftwareFoundation | openexr | < 3.2.11, >= 3.3.0, < 3.3.13, >= 3.4.0, < 3.4.14 |
| AcademySoftwareFoundation | openexr | < 3.2.11, >= 3.3.0, < 3.3.13, >= 3.4.0, < 3.4.14 |
| alpine | openexr | 0, 0, 0 |
Timeline
- Aug 25, 2026 Coalition ESS Score
- Aug 25, 2026 CVE Published
- Aug 26, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 9, 2026 CVE Updated
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Oct 7, 2026 EPSS Score
References
- https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p42q-g5c9-mh9w x_refsource_CONFIRM
- https://github.com/AcademySoftwareFoundation/openexr/commit/0efec58d2d28a0ee322f5028dee6fb57d459580e x_refsource_MISC
- https://github.com/AcademySoftwareFoundation/openexr/commit/78e91146fceeee317820a146ba99a96f380945b8 x_refsource_MISC
- https://github.com/AcademySoftwareFoundation/openexr/commit/f0e404f7298cd8563a1d30a64a1c982dbd68fc49 x_refsource_MISC