#1149061 openexr: CVE-2026-88384

#1149061#5
Date:
2026-09-26 11:54:20 UTC
From:
To:
Hi,

The following vulnerability was published for openexr.

CVE-2026-88384[0]:
| OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++
| attribute parsing path. A specially crafted EXR file containing an
| unknown-type attribute with dataSize set to zero causes the parser
| to create an opaque attribute with a NULL packed_data pointer. The
| OpaqueAttribute constructor passes the NULL pointer to memcpy()
| without validating the zero-size condition, resulting in undefined
| behavior and process termination, leading to denial of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-88384
https://www.cve.org/CVERecord?id=CVE-2026-88384
[1] https://github.com/AcademySoftwareFoundation/openexr/issues/2612
[2] https://github.com/AcademySoftwareFoundation/openexr/pull/2615
[3] https://github.com/AcademySoftwareFoundation/openexr/commit/e782bcc1ffe1cc9edfaa5dbad4f28e866eaf9bbb

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore