Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34588

29
FAUCET Score

CVE-2026-34588 is a signed integer overflow vulnerability in OpenEXR, the motion picture industry standard image file format, affecting versions 3.1.0 through 3.2.6, 3.3.0-3.3.8, and 3.4.0-3.4.8. The flaw exists in the internal_exr_undo_piz() function where signed 32-bit arithmetic on wavelet pointer calculations can overflow, causing subsequent channel decoding to read from and write to incorrect memory addresses, resulting in both out-of-bounds reads and writes. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a local attack vector requiring low privilege but no user interaction. The impact is severe, affecting confidentiality, integrity, and availability with high severity across all three dimensions. An attacker with local access could exploit a maliciously crafted EXR file to leak sensitive information, corrupt data, or cause a denial of service. There is no evidence of active exploitation in the wild, with an exceptionally low EPSS score of 0.000090000 indicating minimal real-world attack probability. The vulnerability does not appear on the CISA KEV catalog and is currently inactive on vulnerability hot lists, suggesting limited community exploitation activity. Security patches are available in OpenEXR versions 3.2.7, 3.3.9, and 3.4.9, which affected organizations should prioritize deploying.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.1.0, < 3.2.7CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
>= 3.3.0, < 3.3.9CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
>= 3.4.0, < 3.4.9CPE matchmatch criteria
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.6HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.48%
Probability of exploitation in next 30 days
EPSS Percentile
38.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0048 is in the 79th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.2.7
pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.3.9
pippatch availablevia ghsa
Product: OpenEXRFixed in: 3.4.9
ubuntupatch availablevia ubuntu_usn
Product: openexr (bionic)Fixed in: 2.2.0-11.1ubuntu1.9+esm1
ubuntupatch availablevia ubuntu_usn
Product: openexr (focal)Fixed in: 2.3.0-6ubuntu0.5+esm2
ubuntupatch availablevia ubuntu_usn
Product: openexr (jammy)Fixed in: 2.5.7-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: openexr (noble)Fixed in: 3.1.5-5.1ubuntu0.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: openexr (resolute)Fixed in: 3.1.13-2ubuntu0.26.04.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: openexr (xenial)Fixed in: 2.2.0-10ubuntu2.6+esm4
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (2)

ubuntuUSN-8259-1

OpenEXR vulnerabilities

May 7, 2026
pipGHSA-588r-cr5c-w6hfhigh

OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write

Apr 8, 2026

References

access.redhat.com / errata/RHSA-2026:15887
access.redhat.com / errata/RHSA-2026:15888
access.redhat.com / errata/RHSA-2026:17656
access.redhat.com / errata/RHSA-2026:17658
access.redhat.com / errata/RHSA-2026:17659
access.redhat.com / errata/RHSA-2026:17660
access.redhat.com / errata/RHSA-2026:19146
access.redhat.com / errata/RHSA-2026:19359
access.redhat.com / errata/RHSA-2026:19587
access.redhat.com / errata/RHSA-2026:30078
access.redhat.com / errata/RHSA-2026:30087
access.redhat.com / errata/RHSA-2026:30088
access.redhat.com / errata/RHSA-2026:30089
access.redhat.com / security/cve/CVE-2026-34588
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-34588.json
github.com / AcademySoftwareFoundation/openexr/releases/tag/v3.2.7
ProductRelease Notes
github.com / AcademySoftwareFoundation/openexr/releases/tag/v3.3.9
ProductRelease Notes
github.com / AcademySoftwareFoundation/openexr/releases/tag/v3.4.9
ProductRelease Notes
github.com / AcademySoftwareFoundation/openexr/security/advisories/GHSA-588r-cr5c-w6hf
ExploitMitigationVendor Advisory