Intel

AIKIDO-2026-10625

AcademySoftwareFoundation.openexr is vulnerable to Integer Overflow

Integer OverflowCVE-2026-40250 Published Apr 28, 2026

82

High Risk

This Affects:

C++AcademySoftwareFoundation.openexr
3.2.0 - 3.2.7
Fixed in 3.2.8
3.3.0 - 3.3.9
Fixed in 3.3.10
3.4.0 - 3.4.9
Fixed in 3.4.10
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to memory corruption when decoding DWA-compressed EXR files. A signed 32-bit multiplication of channel width and bytes-per-element can overflow for crafted dimensions, shifting the end-of-buffer guard and letting the decoder write past the buffer end.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

AcademySoftwareFoundation.openexr is vulnerable to Integer Overflow in versions 3.4.0 - 3.4.9, 3.3.0 - 3.3.9 and 3.2.0 - 3.2.7.

How to fix this

Upgrade the AcademySoftwareFoundation.openexr library to the patch version.