
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27622 is a heap-based buffer overflow vulnerability in OpenEXR's CompositeDeepScanLine::readPixels function caused by a 32-bit integer overflow (wraparound) during per-pixel sample count accumulation. It affects OpenEXR versions 2.3.0 through 3.2.5, 3.3.0 through 3.3.7, and 3.4.0 through 3.4.5, and was disclosed on March 2, 2026 via the GitHub Security Advisory GHSA-cr4v-6jm6-4963. The vulnerability has a CVSS v4.0 base score of 8.4 (High) and a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, OpenEXR Advisory).
The root cause is a 32-bit integer overflow (CWE-190 / CWE-122) in src/lib/OpenEXR/ImfCompositeDeepScanLine.cpp. Per-pixel sample totals are accumulated in a vector<unsigned int> (total_sizes); when an attacker supplies a multipart deep EXR file with many parts and very large per-pixel sample counts, total_sizes[ptr] wraps modulo 2^32. The wrapped (undersized) value is then used to size the composite sample buffer via samples[channel].resize(overall_sample_count), while the decode path (generic_unpack_deep_pointers in src/lib/OpenEXRCore/unpack.c:1374) proceeds using the true, untruncated sample counts, causing a heap out-of-bounds write. Compression (RLE/ZIPS) can be used to keep the malicious file size small (~25 MB) while still triggering the overflow at decode time. A public PoC (writer + reader harness) was included in the advisory and confirmed with AddressSanitizer (OpenEXR Advisory, GitHub Advisory).
Successful exploitation results in a heap out-of-bounds write, which at minimum causes a reliable crash (denial of service) and at worst enables memory corruption leading to potential remote code execution in the context of the application processing the malicious EXR file. All three CIA pillars are rated High: confidentiality (memory disclosure), integrity (heap corruption), and availability (crash/DoS). Any application or pipeline that processes untrusted EXR files using the affected OpenEXR library — including VFX, rendering, and media production software — is at risk (OpenEXR Advisory, GitHub Advisory).
A public proof-of-concept exploit (writer and reader harness) was published alongside the advisory on GitHub, demonstrating reliable heap-buffer-overflow triggering under ASAN (OpenEXR Advisory). The EPSS score is approximately 0.023% (7th percentile), indicating low current probability of active exploitation within 30 days (GitHub Advisory). There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction — a victim must open or process a crafted EXR file.
composite_deep_scanline_e2e_compressed_poc.cpp) to generate a multipart deep EXR file with many parts (e.g., 86 parts) and very large per-pixel sample counts (e.g., 50,000,000 samples per part), using RLE/ZIPS compression to keep the file size manageable (~25 MB while encoding ~4.3 billion true samples).MultiPartInputFile + DeepScanLineInputPart + CompositeDeepScanLine, the readPixels function accumulates per-pixel totals in a vector<unsigned int>. The true total (e.g., 4,300,000,300) wraps modulo 2^32 to a small value (e.g., 5,033,004), causing samples[channel].resize() to allocate an undersized buffer.generic_unpack_deep_pointers) proceeds using the true sample counts, writing far beyond the end of the undersized allocation, corrupting adjacent heap memory at unpack.c:1374..exr files with multipart deep scan line structure delivered via email, download, or shared storage; files with many parts (e.g., 80+) and anomalously large sample count metadata.CompositeDeepScanLine::readPixels, generic_unpack_deep_pointers, or exr_decoding_run; core dumps referencing ImfCompositeDeepScanLine.cpp or unpack.c.heap-buffer-overflow at generic_unpack_deep_pointers (unpack.c:1374); application error logs showing unexpected termination during EXR file processing..exr files from untrusted sources to workstations running VFX, rendering, or media production software.Update OpenEXR to the patched versions: v3.2.6 (for the 3.2.x branch), v3.3.8 (for 3.3.x), or v3.4.6 (for 3.4.x). No configuration-based workaround is available; upgrading is the only definitive fix. As interim mitigations, restrict EXR file processing to trusted sources only, avoid opening EXR files from untrusted parties, and consider sandboxing or privilege-limiting applications that process EXR files. Downstream distributions including Red Hat, Fedora, Ubuntu, AlmaLinux, and Oracle Linux have issued updated packages (OpenEXR Advisory, GitHub Advisory).
The vulnerability was reported by researcher quangIO and sponsored by thaidn, with the advisory published by OpenEXR maintainer cary-ilm on March 2, 2026 (OpenEXR Advisory). Multiple Linux distributions (Red Hat, Fedora, Ubuntu, AlmaLinux, Oracle Linux) responded promptly with security errata. Security scanning vendors including Tenable (Nessus) and Qualys added detection plugins shortly after disclosure. A technical write-up was published at infinitsec.net covering the integer overflow mechanics (GitHub Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
openexr: 2.2.0-11.1ubuntu1.9+esm1
devel
openexr
focal (esm-apps)
openexr: 2.3.0-6ubuntu0.5+esm2
jammy
openexr
jammy (esm-apps)
openexr: 2.5.7-1ubuntu0.1~esm2
noble
openexr
noble (esm-apps)
openexr: 3.1.5-5.1ubuntu0.1~esm1
resolute
openexr
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."