CVE-2026-40250

NameCVE-2026-40250
DescriptionOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan->width * chan->bytes_per_element` in `int32` arithmetic without a `(size_t)` cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses `internal_dwa_compressor.h:1040`.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1134642

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openexr (PTS)bullseye (security), bullseye2.5.4-2+deb11u1vulnerable
bookworm3.1.5-5vulnerable
trixie3.1.13-2vulnerable
forky, sid3.4.6+ds-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openexrsource(unstable)(unfixed)1134642

Notes

https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m5qw-23x2-6phj
https://github.com/AcademySoftwareFoundation/openexr/pull/2346
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/416fecf71241c097d52da5b219d36afd94800e69 (main)
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/42d394a7b761325a3df7c2d57f9dfd905629ca4f (v3.4.10-rc)
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/a41f0d19841469148aabf7e1e056fab9f1c3c4f0 (v3.2.8-rc)

Search for package or bug name: Reporting problems