CVE-2026-27622General(openexr / openexr)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openexr openexr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openexr

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-03); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openexr

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-03: 2Mentions · 2026-03-04: 1Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-17: 103-0303-0403-17
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-032
General2
2026-03-041
Disclosure1
2026-03-171
Patch1
Full discourse4 posts
  • ThreatCluster@threatcluster
    Patch

    Fedora releases security updates for MinGW OpenEXR, addressing CVE-2026-26981 (DoS via heap-buffer overflow) and CVE-2026-27622 (RCE via integer overflow). Update to 3.3.8 or 3.4.6. #Vulnerability https://threatcluster.io/cluster/critical-denial-of-service-vulnerabilities-in-fedoras-mingw--a8c7c9f9

    Post summary

    Fedora released updates for MinGW OpenEXR that patch CVE-2026-26981 (DoS) and CVE-2026-27622 (RCE); users are advised to upgrade to version 3.3.8 or 3.4.6.

    0000055
    103 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27622 OpenEXR Deep Image Format Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27622

    Post summary

    A new vulnerability, CVE-2026-27622, affecting OpenEXR Deep Image Format has been disclosed, with details available on Vulmon.

    0000037
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-27622 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanL… https://www.cve.org/CVERecord?id=CVE-2026-27622 ----- Traducción: CVE-2026-27622 Ope… http://infoflow.cloud`

    Post summary

    The post merely references CVE-2026-27622 and links to its CVE record, offering no additional technical or operational details.

    0000033
    55 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27622 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanL… https://www.cve.org/CVERecord?id=CVE-2026-27622

    Post summary

    The text references CVE-2026-27622 but offers no actionable details on exploitation, patches, or technical specifics.

    00000228
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenexropenexr---

Explore more