CVE-2026-34589 is a buffer overflow vulnerability affecting OpenEXR versions 3.2.0 through 3.2.6, 3.3.0 through 3.3.8, and 3.4.0 through 3.4.8. The DWA lossy decoder incorrectly uses signed 32-bit arithmetic when constructing temporary block pointers, causing integer overflow on large image widths. This results in out-of-bounds memory writes to the rowBlock backing store. The vulnerability has been patched in versions 3.2.7, 3.3.9, and 3.4.9. The vulnerability carries a CVSS 3.1 score of 5.0 (Medium severity) and requires local access with low attack complexity and user interaction. An attacker must be able to supply a specially crafted EXR file to a local user. While the vulnerability does not compromise confidentiality or integrity, it can cause high-impact denial of service by corrupting memory and crashing the application. There is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and has received minimal community attention, with an extremely low EPSS score of 0.000090. Organizations should prioritize patching based on their use of OpenEXR in production environments, but this is not an urgent threat requiring immediate remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.0, < 3.2.7CPE matchmatch criteria | cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.9CPE matchmatch criteria | cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.9CPE matchmatch criteria | cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.