Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

CVE-2026-42217: OpenEXR can crash on specially crafted image files

CVE-2026-42217 · published 4 months ago
Summary

Versions of the OpenEXR library used for handling EXR images (up to 3.2.8, 3.3.10, and 3.4.10) may mishandle certain data and cause the program to stop working. This happens when the library reads a malformed integer value from an untrusted EXR file. Updating to OpenEXR 3.2.9, 3.3.11, or 3.4.11 (or later) resolves the issue.

What to do
  • Update bellsoft openexr to version 3.4.11-r0.
  • Update debian rootio-openexr to version 3.1.5-5.root.io.22.
  • Update debian rootio-openexr to version 3.1.13-2.aikido.15.
  • Update debian rootio-openexr to version 2.5.4-2+deb11u1.root.io.13.
  • Update debian rootio-openexr to version 2.5.4-2+deb11u1.root.io.14.
  • Update debian openexr to version 2.5.4-2+deb11u1.root.io.15.
  • Update debian rootio-openexr to version 2.5.4-2+deb11u1.root.io.15.
  • Update debian openexr to version 2.5.4-2+deb11u1.aikido.18.
  • Update debian rootio-openexr to version 2.5.4-2+deb11u1.aikido.18.
  • Update debian rootio-openexr to version 3.1.5-5.root.io.23.
  • Update debian openexr to version 3.1.5-5.aikido.25.
  • Update debian rootio-openexr to version 3.1.5-5.aikido.25.
  • Update debian rootio-openexr to version 3.1.13-2.root.io.12.
  • Update debian openexr to version 3.1.13-2.root.io.12.
  • Update debian openexr to version 3.1.13-2.aikido.15.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian openexr All versions
Debian:12 debian openexr All versions
Debian:13 debian openexr All versions
Debian:14 debian openexr All versions
– openexr openexr >= 3.0.0, < 3.2.9
>= 3.3.0, < 3.3.11
>= 3.4.0, < 3.4.11
cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*
Alpaquita:stream bellsoft openexr >= 3.4.4-r0, < 3.4.11-r0
Fix: upgrade to 3.4.11-r0
Root:Debian:12 debian rootio-openexr < 3.1.5-5.root.io.22
< 3.1.5-5.root.io.23
< 3.1.5-5.aikido.25
Fix: upgrade to 3.1.5-5.root.io.22
Root:Debian:13 debian rootio-openexr < 3.1.13-2.aikido.15
< 3.1.13-2.root.io.12
Fix: upgrade to 3.1.13-2.aikido.15
Root:Debian:11 debian rootio-openexr < 2.5.4-2+deb11u1.root.io.13
< 2.5.4-2+deb11u1.root.io.14
< 2.5.4-2+deb11u1.root.io.15
< 2.5.4-2+deb11u1.aikido.18
Fix: upgrade to 2.5.4-2+deb11u1.root.io.13
Root:Debian:11 debian openexr < 2.5.4-2+deb11u1.root.io.15
< 2.5.4-2+deb11u1.aikido.18
Fix: upgrade to 2.5.4-2+deb11u1.root.io.15
Root:Debian:12 debian openexr < 3.1.5-5.aikido.25
Fix: upgrade to 3.1.5-5.aikido.25
Root:Debian:13 debian openexr < 3.1.13-2.root.io.12
< 3.1.13-2.aikido.15
Fix: upgrade to 3.1.13-2.root.io.12
Original advisory text
OpenEXR: Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`)
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
Severity
7.8 High
CVSS 4.0: 6.3 (NVD)
CVSS 3.1: 9.8 (OSV)
CVSS 4.0: 7.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-190Integer Overflow
Timeline
Published7 May 2026
Updated25 Sep 2026
First seen7 May 2026
Track software like this
Free during beta