LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-68515

Published
CVSS7.1
Severityhigh
WeaknessCWE-122
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Description

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr

References

← Back to the CVE Tracker

Our coverage of CVE-2026-68515

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-68515.