Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the HTJ2K decoder parses a header-length field (PLEN) from a chunk's compressed data but never checks that this value fits within the available buffer before using it. When decoding, it advances the codestream pointer by the attacker-supplied header size and passes the resulting offset and remaining length to the OpenJPH memory-input path, so a crafted value pushes the pointer past the end of the buffer and causes an out-of-bounds read. Because this field comes straight from attacker-controlled EXR chunk data, the flaw is reachable during normal decoding of an untrusted file. This issue is fixed in version 3.4.13. | |
| Title | OpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN) | |
| Weaknesses | CWE-125 CWE-20 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T19:16:25.169Z
Reserved: 2026-07-23T18:54:15.831Z
Link: CVE-2026-65979
Updated: 2026-08-25T19:16:18.869Z
Status : Received
Published: 2026-08-25T19:16:52.307
Modified: 2026-08-25T20:17:01.020
Link: CVE-2026-65979
No data.
OpenCVE Enrichment
No data.