🔐 CVE Alert

CVE-2026-34379

HIGH 7.1

OpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression)

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

CWE CWE-704 CWE-787 CWE-843
Vendor academysoftwarefoundation
Product openexr
Published Apr 6, 2026
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for academysoftwarefoundation openexr

Be the first to know when new high vulnerabilities affecting academysoftwarefoundation openexr are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High

Affected Versions

AcademySoftwareFoundation / openexr
>= 3.2.0, < 3.2.7 >= 3.3.0, < 3.3.9 >= 3.4.0, < 3.4.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-w88v-vqhq-5p24 github.com: https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7 github.com: https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9 github.com: https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9