REDHAT-BUG-2459955: High severity OpenEXR OpenEXR vulnerability
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, internaldwacompressor.h:1722 performs curc->width curc->height in int32 arithmetic without a (sizet) cast. This is the same overflow pattern fixed in other locations by the recent CVE-2026-34589 batch, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses internaldwacompressor.h:1722.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.4.10 - Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.3.10 - Upgrade
Upgrade
OpenEXRto a version that resolves this vulnerability.Fixed in 3.2.8
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2459955?
The severity of REDHAT-BUG-2459955 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2459955?
To fix REDHAT-BUG-2459955, upgrade OpenEXR to a version greater than 3.4.9, 3.3.9, or 3.2.7.
What versions of OpenEXR are affected by REDHAT-BUG-2459955?
OpenEXR versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7 are affected by REDHAT-BUG-2459955.
What is the impact of REDHAT-BUG-2459955?
The impact of REDHAT-BUG-2459955 could lead to a denial of service or potentially allow an attacker to exploit the vulnerability.
When was REDHAT-BUG-2459955 published?
REDHAT-BUG-2459955 was published on April 21, 2026.