← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 25, 2026 · 00:16via CVEFeed

CVE-2026-55059 - OpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds write vulnerability

Brief

CVE ID : CVE-2026-55059

Published : Aug. 25, 2026, 12:16 a. m.

  • 56 minutes ago

Description : OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.

  • 10, 3.
  • 12 and 3.
  • 13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]). The row-based sample-count setter computes the target Y coordinate with dataWindow. min. x instead of dataWindow. min.

y. For a valid deep image data window where min. x ! = min. y, a valid row index can be translated into an invalid Y coordinate, causing writes before the allocated _numSamples buffer. The vulnerability is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. This issue has been fixed in versions 3.

  • 10, 3.
  • 12 and 3.
  • 13.
Read more on CVEFeed