CVE-2026-59189
Received Received - Intake

Heap Out-of-Bounds Read in OpenEXRUtil via TypedDeepImageChannel

Vulnerability report for CVE-2026-59189, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: GitHub, Inc.

Description

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 12 associated CPEs
Vendor Product Version / Range
academysoftwarefoundation openexrutil 2.*
academysoftwarefoundation openexrutil 3.0.*
academysoftwarefoundation openexrutil 3.1.*
academysoftwarefoundation openexrutil 3.2.0
academysoftwarefoundation openexrutil 3.3.0
academysoftwarefoundation openexrutil 3.4.0
academysoftwarefoundation openexrutil 3.2.11
academysoftwarefoundation openexrutil 3.3.13
academysoftwarefoundation openexrutil 3.4.14
openexr openexrutil From 3.3.0 (inc) to 3.4.12 (inc)
openexr openexrutil 3.3.13
openexr openexrutil 3.4.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-59189 is a heap out-of-bounds read vulnerability in OpenEXRUtil affecting versions 3.3.0-3.3.12 and 3.4.0-3.4.12. It occurs when the TypedDeepImageChannel<T>::row() API returns an out-of-bounds pointer for deep images with a non-zero dataWindow origin. This happens due to conflicting coordinate models between absolute and logical access methods.

Detection Guidance

Detecting this vulnerability requires checking the installed version of OpenEXRUtil. Run 'openexrutil --version' or check package managers like 'dpkg -l | grep openexr' or 'rpm -qa | grep openexr'. Versions 3.3.0-3.3.12, 3.4.0-3.4.12, or 2.* are vulnerable.

Impact Analysis

This vulnerability can crash applications via segmentation faults or heap buffer overflows. It may also lead to potential information disclosure under specific heap layouts, though arbitrary code execution was not confirmed. The impact is limited to availability and confidentiality.

Mitigation Strategies

Upgrade OpenEXRUtil to patched versions 3.3.13, 3.4.13, or 3.2.11. If using 2.*, upgrade to a supported version. Avoid processing deep images with non-zero dataWindow origins until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59189. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart