← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 25, 2026 · 20:16via CVEFeed

CVE-2026-59981 - OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow

Brief

CVE ID : CVE-2026-59981

Published : Aug. 25, 2026, 8:16 p. m.

  • 55 minutes ago

Description : OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.

  • 10, 3.
  • 0 through 3.
  • 12, and 3.
  • 0 through 3.
  • 13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin.

The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow. min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer.

Read more on CVEFeed