Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.8
CVE-2026-42217: OpenEXR can crash on specially crafted image files
CVE-2026-42217 · published 4 months ago
Summary
Versions of the OpenEXR library used for handling EXR images (up to 3.2.8, 3.3.10, and 3.4.10) may mishandle certain data and cause the program to stop working. This happens when the library reads a malformed integer value from an untrusted EXR file. Updating to OpenEXR 3.2.9, 3.3.11, or 3.4.11 (or later) resolves the issue.
What to do
- Update bellsoft openexr to version 3.4.11-r0.
- Update debian rootio-openexr to version 3.1.5-5.root.io.22.
- Update debian rootio-openexr to version 3.1.13-2.aikido.15.
- Update debian rootio-openexr to version 2.5.4-2+deb11u1.root.io.13.
- Update debian rootio-openexr to version 2.5.4-2+deb11u1.root.io.14.
- Update debian openexr to version 2.5.4-2+deb11u1.root.io.15.
- Update debian rootio-openexr to version 2.5.4-2+deb11u1.root.io.15.
- Update debian openexr to version 2.5.4-2+deb11u1.aikido.18.
- Update debian rootio-openexr to version 2.5.4-2+deb11u1.aikido.18.
- Update debian rootio-openexr to version 3.1.5-5.root.io.23.
- Update debian openexr to version 3.1.5-5.aikido.25.
- Update debian rootio-openexr to version 3.1.5-5.aikido.25.
- Update debian rootio-openexr to version 3.1.13-2.root.io.12.
- Update debian openexr to version 3.1.13-2.root.io.12.
- Update debian openexr to version 3.1.13-2.aikido.15.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | openexr | All versions |
| Debian:12 | debian | openexr | All versions |
| Debian:13 | debian | openexr | All versions |
| Debian:14 | debian | openexr | All versions |
| – | openexr | openexr |
>= 3.0.0, < 3.2.9 >= 3.3.0, < 3.3.11 >= 3.4.0, < 3.4.11 cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:* |
| Alpaquita:stream | bellsoft | openexr |
>= 3.4.4-r0, < 3.4.11-r0 Fix: upgrade to 3.4.11-r0
|
| Root:Debian:12 | debian | rootio-openexr |
< 3.1.5-5.root.io.22 < 3.1.5-5.root.io.23 < 3.1.5-5.aikido.25 Fix: upgrade to 3.1.5-5.root.io.22
|
| Root:Debian:13 | debian | rootio-openexr |
< 3.1.13-2.aikido.15 < 3.1.13-2.root.io.12 Fix: upgrade to 3.1.13-2.aikido.15
|
| Root:Debian:11 | debian | rootio-openexr |
< 2.5.4-2+deb11u1.root.io.13 < 2.5.4-2+deb11u1.root.io.14 < 2.5.4-2+deb11u1.root.io.15 < 2.5.4-2+deb11u1.aikido.18 Fix: upgrade to 2.5.4-2+deb11u1.root.io.13
|
| Root:Debian:11 | debian | openexr |
< 2.5.4-2+deb11u1.root.io.15 < 2.5.4-2+deb11u1.aikido.18 Fix: upgrade to 2.5.4-2+deb11u1.root.io.15
|
| Root:Debian:12 | debian | openexr |
< 3.1.5-5.aikido.25 Fix: upgrade to 3.1.5-5.aikido.25
|
| Root:Debian:13 | debian | openexr |
< 3.1.13-2.root.io.12 < 3.1.13-2.aikido.15 Fix: upgrade to 3.1.13-2.root.io.12
|
Original advisory text
OpenEXR: Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`)
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
References
- https://docs.bell-sw.com/security/cves/CVE-2026-42217 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-42217 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42217 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42217... Vendor Advisory
- https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3c... Vendor Advisory
- https://github.com/AcademySoftwareFoundation/openexr/commit/21eaa33bcbbb0c83a5fc... Patch
- https://github.com/AcademySoftwareFoundation/openexr/pull/2378 Patch
Severity
7.8
High
CVSS 4.0: 6.3 (NVD)
CVSS 3.1: 9.8 (OSV)
CVSS 4.0: 7.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-190Integer Overflow
Timeline
Published7 May 2026
Updated25 Sep 2026
First seen7 May 2026
Sources
CVE-2026-42217 · NVD
DEBIAN-CVE-2026-42217 · OSV
BELL-CVE-2026-42217 · OSV
CVE-2026-42217 · OSV
GHSA-3c67-4wwp-w52m · GHSA
Track software like this
Free during beta