OpenEXR是Academy Software Foundation开源的一种高动态范围图像(HDR)文件格式的开放标准。 OpenEXR 3.1.0至3.2.7之前版本、3.3.9之前版本和3.4.9之前版本存在缓冲区错误漏洞,该漏洞源于整数溢出可能导致越界读取和越界写入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AcademySoftwareFoundation | openexr | >= 3.1.0, <= 3.1.13 |
affected |
>= 3.2.0, < 3.2.7 |
affected | ||
>= 3.3.0, < 3.3.9 |
affected | ||
>= 3.4.0, < 3.4.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AcademySoftwareFoundation | openexr | >= 3.1.0, <= 3.1.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34379 | 7.1 HIGH | OpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (D |
| CVE-2026-34378 | 6.5 MEDIUM | OpenEXR has a signed integer overflow in generic_unpack() when parsing EXR files with craf |
| CVE-2026-34380 | 5.9 MEDIUM | OpenEXR has a signed integer overflow (undefined behavior) in undo_pxr24_impl may allow bo |
| CVE-2026-34589 | OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write |
No comments yet