PatchSiren

AcademySoftwareFoundation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-68515

The OpenEXR library, widely used in the motion picture industry for handling EXR image files, contains a vulnerability in its exrmultiview utility. This utility can write past a heap allocation when combining two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The vulnerability is triggered by normal public-tool processing a [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-68514

A heap out-of-bounds write vulnerability exists in OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, specifically in the PyOpenEXR Python bindings. This issue is triggered when reading a crafted deep scanline EXR file, leading to memory corruption and a crash. The vulnerability is fixed in versions 3.3.13 and 3.4.14. Defenders responsible for systems using OpenEXR, particularly in the motion [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-68513

A heap buffer overflow vulnerability exists in OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, specifically in PyOpenEXR when handling a crafted flat scanline EXR file with a channel-name key collision between literal and prefixed RGB channels. This vulnerability can lead to potential arbitrary code execution, emphasizing the need for verification of exposure and prioritization of updates [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59981

CVE-2026-59981 is a vulnerability in the OpenEXR library, which is used for reading and writing EXR image files. The vulnerability occurs when a deep image has a non-zero dataWindow origin, causing the SampleCountChannel::row() API to return an out-of-bounds pointer. This can lead to an out-of-bounds read, potentially crashing the process or returning adjacent heap memory as sample-count values.

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-65979

CVE-2026-65979 is a vulnerability in OpenEXR, a widely used image format in the motion picture industry. The vulnerability exists in versions 3.4.0 through 3.4.12 and allows for an out-of-bounds read when decoding an untrusted file. This issue is fixed in version 3.4.13. The vulnerability is caused by the HTJ2K decoder parsing a header-length field from a chunk's compressed data without checking if it fit [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-62986

CVE-2026-62986 is a vulnerability in OpenEXR, a widely used image file format in the motion picture industry. The issue affects versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, where the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR file. This can lead to exposure of uninitialized same-process heap contents and incorrect green and blue channel data when p [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59985

CVE-2026-59985 is a vulnerability in OpenEXR, a reference implementation and specification for the EXR image format. A heap out-of-bounds read issue exists in OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 on ILP32 builds. This issue can cause denial of service when a crafted RLE-compressed EXR file is processed. The vulnerability is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59984

CVE-2026-59984 is a vulnerability in OpenEXR, a reference implementation and specification for the EXR image format. A crafted B44-compressed scanline EXR can cause an out-of-bounds write, leading to denial of service and memory corruption on ILP32 builds of OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59983

CVE-2026-59983 is a vulnerability in OpenEXR, a reference implementation and specification for the EXR image format widely used in the motion picture industry. A crafted uncompressed deep-tile EXR can cause an out-of-bounds read, leading to denial of service on ILP32 builds. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. The vulnerability is caused by an out-of-bounds read when decoding a cra [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59982

CVE-2026-59982 is a vulnerability in OpenEXR, a widely used image format in the motion picture industry. A crafted deep EXR image can cause an out-of-bounds pointer return, potentially leading to a crash or limited information disclosure. The issue is fixed in OpenEXR versions 3.2.11, 3.3.13, and 3.4.14. This vulnerability affects systems and applications using OpenEXR, particularly in the motion picture [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59189

CVE-2026-59189 is a heap out-of-bounds read vulnerability in OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12. The vulnerability arises from the TypedDeepImageChannel<T>::row() API returning an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a crash and potential information disclosure. This issue is fixed in versions 3.3.13 and 3.4.13.

HIGH AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59187

A heap out-of-bounds write vulnerability exists in OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 when processing crafted deep scanline EXR images with specific pixel conversion options. This issue is fixed in versions 3.3.13 and 3.4.14. The vulnerability can lead to data corruption or crashes, and defenders in the motion picture industry or other environments using OpenEXR should assess e [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59186

CVE-2026-59186 is a heap out-of-bounds write vulnerability in OpenEXR, a widely used image format in the motion picture industry. The vulnerability affects versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13. A crafted tiled EXR image can trigger the vulnerability when read through the public TiledRgbaInputFile RGBA API on 32-bit/ILP32 builds. The issue is fixed in versions 3.2.11, 3.3. [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59184

CVE-2026-59184 is a vulnerability in OpenEXR, a widely used image format in the motion picture industry. A crafted EXR file can cause out-of-bounds or use-after-free writes when processed by certain applications. This issue is fixed in OpenEXR versions 3.2.11, 3.3.13, and 3.4.14. The vulnerability occurs when a crafted EXR file with a nonzero dataWindow.min is processed, causing out-of-bounds or use-after [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-59183

A vulnerability in OpenEXR, a widely used image format in the motion picture industry, can cause a crash when decoding crafted deep tiled EXR files. The issue arises from an int32_t multiplication overflow in the unpack_sample_table() function, leading to an invalid pointer and a read from an unmapped memory address. This affects applications that decode deep tiled EXR files. Fixes are available in versio [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-55373

CVE-2026-55373 is a medium-severity vulnerability affecting OpenEXR, a widely used image format in the motion picture industry. The issue, caused by an infinite-loop vulnerability in SampleCountChannel, can be triggered through public OpenEXRUtil APIs. This vulnerability has been fixed in OpenEXR versions 3.2.10, 3.3.12, and 3.4.13. Affected product deployments should be assessed for exposure, and defende [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-55371

A NULL pointer dereference vulnerability exists in OpenEXR versions 3.4.0 through 3.4.12. The issue is fixed in version 3.4.13. This vulnerability results in a denial of service. Defenders should assess exposure and prioritize verification and mitigation for systems and software using OpenEXR, focusing on version upgrades and compensating controls. The vulnerability is caused by a NULL pointer dereference [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-55059

A heap out-of-bounds write vulnerability exists in OpenEXR versions prior to 3.2.10, 3.3.12, and 3.4.13. This issue is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. The vulnerability is caused by a row-based sample-count setter computing the target Y coordinate with dataWindow.min.x instead of dataWindow.min.y.

NONE AcademySoftwareFoundation CVE published 2026-08-25

CVE-2026-54920

CVE-2026-54920 is a denial-of-service vulnerability in OpenEXR, a widely used image format in the motion picture industry. A crafted HTJ2K-compressed EXR file can cause an unconditional process abort in applications that call exr_start_read() on untrusted input. This issue has been resolved in version 3.4.13. The vulnerability is triggered by a QCD marker whose lower five bits are zero, which OpenEXR pass [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-08-24

CVE-2026-53532

CVE-2026-53532 is a denial-of-service vulnerability affecting OpenEXR versions 3.4.0 through 3.4.12. A crafted HTJ2K-compressed EXR file can cause an unconditional process abort when processed by applications calling exr_start_read() on untrusted input. This issue has been resolved in version 3.4.13. The vulnerability is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into t [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-08-24

CVE-2026-68516

CVE-2026-68516 is a denial-of-service vulnerability affecting OpenEXR versions 3.4.0 through 3.4.13. A crafted HTJ2K-compressed EXR image can cause a stack out-of-bounds write during normal decode, leading to a crash. This issue is fixed in OpenEXR version 3.4.14. The vulnerability is particularly concerning for the motion picture industry, which heavily utilizes the EXR image format. Defenders should ass [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-06-18

CVE-2026-45696

CVE-2026-45696 is a high-severity vulnerability in OpenEXR, a widely-used image format in the motion picture industry. A heap-buffer-overflow READ vulnerability exists in the HTJ2K decoder, ht_undo_impl() in OpenEXRCore, affecting versions 3.4.0 through 3.4.11. The vulnerability occurs when the ht_undo_impl function copies decoded pixels out of a per-line OpenJPH buffer using the EXR channel's declared wi [truncated]

MEDIUM AcademySoftwareFoundation CVE published 2026-06-18

CVE-2026-44663

CVE-2026-44663 is a heap-buffer overflow vulnerability in OpenEXR, a widely used image format in the motion picture industry. The vulnerability exists in the ht_undo_impl() function in src/lib/OpenEXRCore/internal_ht.cpp, where an integer overflow occurs when decoding a crafted HTJ2K-compressed EXR file. This leads to a corrupted offset used for pointer arithmetic, causing a heap out-of-bounds write. The [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-05-07

CVE-2026-42216

CVE-2026-42216 is a high-severity vulnerability in OpenEXR, an image storage format for the motion picture industry. The vulnerability affects versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11. The issue arises from the IDManifest::init() function, which reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-05-07

CVE-2026-41142

CVE-2026-41142 is an integer overflow vulnerability in the OpenEXR image storage format, specifically in the ImageChannel::resize function. This issue affects OpenEXR versions from 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11. The vulnerability leads to a heap out-of-bounds write via the OpenEXRUtil public API, posing a significant risk to applications utilizing OpenEXR. The C [truncated]

HIGH AcademySoftwareFoundation CVE published 2026-04-21

CVE-2026-40244

CVE-2026-40244 is a high-severity vulnerability in OpenEXR, an image storage format used in the motion picture industry. The vulnerability affects OpenEXR versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7. The issue is caused by an integer overflow in the `internal_dwa_compressor.h` file, which can lead to potential code execution. The vulnerability has a CVSS score of 8.4 and is [truncated]