REDHAT-BUG-2490597: High severity OpenEXR OpenEXR vulnerability

Published Jun 18, 2026
·
Updated

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, htundoimpl() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ. The htundoimp function copies decoded pixels out of a per-line OpenJPH buffer using the EXR channel's declared width as the iteration count. The codestream embedded in the EXR chunk can declare different (smaller) tile/line dimensions than the EXR header advertises, but htundoimpl() does not validate this — it pulls width 32-bit samples from curline->i32[] without checking the OpenJPH line buffer's actual length. A crafted EXR file produces a 4-byte heap-buffer-overflow READ immediately after a buffer allocated by ojph::local::codestream::finalizealloc(). The bug is reachable through the standard scanline-decode entry point used by every consumer of exrdecodingrun/Imf::checkOpenEXRFile, including thumbnailers, asset pipelines, and the exrcheck utility — i.e. any application that opens untrusted EXR files. The result is a deterministic crash (DoS) and potential adjacent-heap leak. This issue has been fixed in version 3.4.12.

Affected Software

1 affected component
OpenEXR OpenEXR>=3.4.0<=3.4.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenEXR to a version that resolves this vulnerability.

    Fixed in 3.4.12

Event History

Jun 18, 2026
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2490597?

The severity of REDHAT-BUG-2490597 is high, rated at 7.

2

What vulnerability is present in REDHAT-BUG-2490597?

REDHAT-BUG-2490597 describes a heap-buffer-overflow READ vulnerability in the HTJ2K decoder of OpenEXR.

3

Which versions are affected by REDHAT-BUG-2490597?

Versions 3.4.0 through 3.4.11 of OpenEXR are affected by REDHAT-BUG-2490597.

4

How do I fix REDHAT-BUG-2490597?

To resolve REDHAT-BUG-2490597, upgrade to a fixed version of OpenEXR that addresses this vulnerability.

5

What impact does REDHAT-BUG-2490597 have on applications?

The impact of REDHAT-BUG-2490597 could potentially allow an attacker to exploit the heap-buffer-overflow vulnerability, leading to possible application crashes or arbitrary code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203