Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-68516— OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow

Quick assessment

Affected
AcademySoftwareFoundation openexr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenEXR 是 EXR 图像格式的参考实现和标准规范,广泛应用于电影行业。在版本 3.4.0 到 3.4.13 中,精心构造的经过 HTJ2K 压缩的 EXR 文件可在正常解码过程中导致 OpenEXR 崩溃。当 HTJ2K 压缩的 EXR 文件中 JPEG 2000 的 SIZ 字段将第一个图块(tile)放置在可见图像区域之外时,会导致在内置的 OpenJPH AVX2 解码器中出现非法的图块和代码块几何结构,从而引发栈越界写(stack out-of-bounds write)并导致拒绝服务(Denial

CVSS 6.5 · Medium EPSS 0.25% · P16

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
AcademySoftwareFoundation openexr >= 3.4.0, < 3.4.14 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-68516

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow
Source: CVE Program / CVE List V5
Vulnerability Description
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
AcademySoftwareFoundation openexr >= 3.4.0, < 3.4.14 -

II. Public POCs for CVE-2026-68516

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-68516

登录查看更多情报信息。

Vendor Advisories for CVE-2026-68516 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-68516

No comments yet


Leave a comment