Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27622

29
FAUCET Score

CVE-2026-27622 is a high-severity vulnerability affecting OpenEXR, an image storage format used in the motion picture industry. The flaw, located in the CompositeDeepScanLine::readPixels function, allows an attacker to cause a heap buffer overflow by manipulating per-pixel totals, leading to undersized sample buffers. This can result in arbitrary code execution, data compromise, or denial of service, with a CVSS score of 7.8. While no active exploitation or public exploit code has been observed, and community discussion is minimal, the vulnerability is fixed in OpenEXR versions v3.2.6, v3.3.8, and v3.4.6.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.6CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
>= 3.3.0, < 3.3.8CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
>= 3.4.0, < 3.4.6CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.4HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
10.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 8th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.2.6
pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.3.8
pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.4.6
ubuntupatch availablevia ubuntu_usn
Product: openexr (jammy)Fixed in: 2.5.7-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: openexr (noble)Fixed in: 3.1.5-5.1ubuntu0.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: openexr (resolute)Fixed in: 3.1.13-2ubuntu0.26.04.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: openexr (xenial)Fixed in: 2.2.0-10ubuntu2.6+esm4
ubuntupatch availablevia ubuntu_usn
Product: openexr (bionic)Fixed in: 2.2.0-11.1ubuntu1.9+esm1
ubuntupatch availablevia ubuntu_usn
Product: openexr (focal)Fixed in: 2.3.0-6ubuntu0.5+esm2
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

ubuntuUSN-8259-1

OpenEXR vulnerabilities

May 7, 2026
pipGHSA-cr4v-6jm6-4963high

OpenEXR's CompositeDeepScanLine integer-overflow leads to heap OOB write

Mar 2, 2026

References

access.redhat.com / errata/RHSA-2026:12338
access.redhat.com / errata/RHSA-2026:12339
access.redhat.com / errata/RHSA-2026:12340
access.redhat.com / errata/RHSA-2026:12341
access.redhat.com / errata/RHSA-2026:16008
access.redhat.com / errata/RHSA-2026:16009
access.redhat.com / errata/RHSA-2026:16030
access.redhat.com / errata/RHSA-2026:16174
access.redhat.com / errata/RHSA-2026:7678
access.redhat.com / errata/RHSA-2026:7682
access.redhat.com / errata/RHSA-2026:8863
access.redhat.com / errata/RHSA-2026:8869
access.redhat.com / errata/RHSA-2026:8870
access.redhat.com / errata/RHSA-2026:8871
access.redhat.com / errata/RHSA-2026:8872
access.redhat.com / errata/RHSA-2026:8888
access.redhat.com / security/cve/CVE-2026-27622
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-27622.json
github.com / AcademySoftwareFoundation/openexr/security/advisories/GHSA-cr4v-6jm6-4963
ExploitVendor Advisory