CVE-2026-34588 is a signed integer overflow vulnerability in OpenEXR, the motion picture industry standard image file format, affecting versions 3.1.0 through 3.2.6, 3.3.0-3.3.8, and 3.4.0-3.4.8. The flaw exists in the internal_exr_undo_piz() function where signed 32-bit arithmetic on wavelet pointer calculations can overflow, causing subsequent channel decoding to read from and write to incorrect memory addresses, resulting in both out-of-bounds reads and writes. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a local attack vector requiring low privilege but no user interaction. The impact is severe, affecting confidentiality, integrity, and availability with high severity across all three dimensions. An attacker with local access could exploit a maliciously crafted EXR file to leak sensitive information, corrupt data, or cause a denial of service. There is no evidence of active exploitation in the wild, with an exceptionally low EPSS score of 0.000090000 indicating minimal real-world attack probability. The vulnerability does not appear on the CISA KEV catalog and is currently inactive on vulnerability hot lists, suggesting limited community exploitation activity. Security patches are available in OpenEXR versions 3.2.7, 3.3.9, and 3.4.9, which affected organizations should prioritize deploying.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.0, < 3.2.7CPE matchmatch criteria | cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.9CPE matchmatch criteria | cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.9CPE matchmatch criteria | cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.