CVE-2026-27622: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27622 is a heap-based buffer overflow vulnerability in OpenEXR's CompositeDeepScanLine::readPixels function caused by a 32-bit integer overflow (wraparound) during per-pixel sample count accumulation. It affects OpenEXR versions 2.3.0 through 3.2.5, 3.3.0 through 3.3.7, and 3.4.0 through 3.4.5, and was disclosed on March 2, 2026 via the GitHub Security Advisory GHSA-cr4v-6jm6-4963. The vulnerability has a CVSS v4.0 base score of 8.4 (High) and a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, OpenEXR Advisory).

Technical details

The root cause is a 32-bit integer overflow (CWE-190 / CWE-122) in src/lib/OpenEXR/ImfCompositeDeepScanLine.cpp. Per-pixel sample totals are accumulated in a vector<unsigned int> (total_sizes); when an attacker supplies a multipart deep EXR file with many parts and very large per-pixel sample counts, total_sizes[ptr] wraps modulo 2^32. The wrapped (undersized) value is then used to size the composite sample buffer via samples[channel].resize(overall_sample_count), while the decode path (generic_unpack_deep_pointers in src/lib/OpenEXRCore/unpack.c:1374) proceeds using the true, untruncated sample counts, causing a heap out-of-bounds write. Compression (RLE/ZIPS) can be used to keep the malicious file size small (~25 MB) while still triggering the overflow at decode time. A public PoC (writer + reader harness) was included in the advisory and confirmed with AddressSanitizer (OpenEXR Advisory, GitHub Advisory).

Impact

Successful exploitation results in a heap out-of-bounds write, which at minimum causes a reliable crash (denial of service) and at worst enables memory corruption leading to potential remote code execution in the context of the application processing the malicious EXR file. All three CIA pillars are rated High: confidentiality (memory disclosure), integrity (heap corruption), and availability (crash/DoS). Any application or pipeline that processes untrusted EXR files using the affected OpenEXR library — including VFX, rendering, and media production software — is at risk (OpenEXR Advisory, GitHub Advisory).

Exploitability

A public proof-of-concept exploit (writer and reader harness) was published alongside the advisory on GitHub, demonstrating reliable heap-buffer-overflow triggering under ASAN (OpenEXR Advisory). The EPSS score is approximately 0.023% (7th percentile), indicating low current probability of active exploitation within 30 days (GitHub Advisory). There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction — a victim must open or process a crafted EXR file.

Exploitation steps

  1. Craft malicious EXR file: Use the published PoC writer (composite_deep_scanline_e2e_compressed_poc.cpp) to generate a multipart deep EXR file with many parts (e.g., 86 parts) and very large per-pixel sample counts (e.g., 50,000,000 samples per part), using RLE/ZIPS compression to keep the file size manageable (~25 MB while encoding ~4.3 billion true samples).
  2. Trigger integer overflow: When the victim application opens the file using MultiPartInputFile + DeepScanLineInputPart + CompositeDeepScanLine, the readPixels function accumulates per-pixel totals in a vector<unsigned int>. The true total (e.g., 4,300,000,300) wraps modulo 2^32 to a small value (e.g., 5,033,004), causing samples[channel].resize() to allocate an undersized buffer.
  3. Trigger heap OOB write: The decode path (generic_unpack_deep_pointers) proceeds using the true sample counts, writing far beyond the end of the undersized allocation, corrupting adjacent heap memory at unpack.c:1374.
  4. Achieve impact: Depending on heap layout and target application, the result is a crash (DoS) or, with further exploit engineering, potential arbitrary code execution in the context of the EXR-processing application (OpenEXR Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Unexpected or unusually large .exr files with multipart deep scan line structure delivered via email, download, or shared storage; files with many parts (e.g., 80+) and anomalously large sample count metadata.
  • Process: Application crashes (segmentation faults, abort signals) in processes loading EXR files, particularly in functions such as CompositeDeepScanLine::readPixels, generic_unpack_deep_pointers, or exr_decoding_run; core dumps referencing ImfCompositeDeepScanLine.cpp or unpack.c.
  • Logs: Crash reports or ASAN output referencing heap-buffer-overflow at generic_unpack_deep_pointers (unpack.c:1374); application error logs showing unexpected termination during EXR file processing.
  • Network: Unusual inbound delivery of .exr files from untrusted sources to workstations running VFX, rendering, or media production software.

Mitigation and workarounds

Update OpenEXR to the patched versions: v3.2.6 (for the 3.2.x branch), v3.3.8 (for 3.3.x), or v3.4.6 (for 3.4.x). No configuration-based workaround is available; upgrading is the only definitive fix. As interim mitigations, restrict EXR file processing to trusted sources only, avoid opening EXR files from untrusted parties, and consider sandboxing or privilege-limiting applications that process EXR files. Downstream distributions including Red Hat, Fedora, Ubuntu, AlmaLinux, and Oracle Linux have issued updated packages (OpenEXR Advisory, GitHub Advisory).

Community reactions

The vulnerability was reported by researcher quangIO and sponsored by thaidn, with the advisory published by OpenEXR maintainer cary-ilm on March 2, 2026 (OpenEXR Advisory). Multiple Linux distributions (Red Hat, Fedora, Ubuntu, AlmaLinux, Oracle Linux) responded promptly with security errata. Security scanning vendors including Tenable (Nessus) and Qualys added detection plugins shortly after disclosure. A technical write-up was published at infinitsec.net covering the integer overflow mechanics (GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

openexr

Affected

sid

openexr: 3.4.6+ds-1

Fixed

trixie

openexr

Affected

Ubuntu

Fixed

bionic (esm-infra)

openexr: 2.2.0-11.1ubuntu1.9+esm1

Fixed

devel

openexr

Not Affected

focal (esm-apps)

openexr: 2.3.0-6ubuntu0.5+esm2

Fixed

jammy

openexr

Affected

jammy (esm-apps)

openexr: 2.5.7-1ubuntu0.1~esm2

Fixed

noble

openexr

Affected

noble (esm-apps)

openexr: 3.1.5-5.1ubuntu0.1~esm1

Fixed

resolute

openexr

Affected

RHEL / CentOS

Fixed

RHEL 8

:appstream:OpenEXR-0:2.2.0-12.el8_10.1.src

Fixed

RHEL 9

:appstream:openexr-0:3.1.1-2.el9_0.2.src

Fixed

RHEL 10

openexr-0:3.1.10-8.el10_0.1.src

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management