
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34543 is a heap information disclosure vulnerability in OpenEXR's PXR24 decompression implementation, classified as "Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)." It affects OpenEXR versions 3.2.0–3.2.6, 3.3.0–3.3.8, and 3.4.0–3.4.7. The vulnerability was published on March 27, 2026, and patched in versions 3.2.7, 3.3.9, and 3.4.8. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Github Advisory, OpenEXR Advisory).
The vulnerability (CWE-908: Use of Uninitialized Resource) arises from two compounding flaws in OpenEXR's PXR24 decompression path. First, in compression.c (lines 202–205), the exr_uncompress_buffer() function treats LIBDEFLATE_SHORT_OUTPUT — a condition where the zlib stream decompresses to fewer bytes than the output buffer — as a success rather than an error, writing the actual byte count to actual_out but returning EXR_ERR_SUCCESS. Second, in internal_pxr24.c, the undo_pxr24_impl() function (lines 261–399) ignores the returned outSize value and instead reads from the scratch buffer based solely on uncompressed_size derived from the file's header metadata. An attacker can craft a PXR24 EXR file with a valid but truncated zlib stream, causing the decoder to read uninitialized heap memory in the region between outSize and uncompressed_size and incorporate it into the output pixel data. A proof-of-concept with reproducible steps is publicly available (OpenEXR Advisory, Patch Commit).
Successful exploitation results in a high-confidentiality-impact information disclosure: sensitive heap memory contents are leaked through the decoded pixel data of the processed EXR image. No integrity or availability impact is associated with this vulnerability. The attack requires no authentication, no privileges, and no user interaction beyond the application reading a malicious EXR file, making it exploitable in any context where untrusted EXR files are processed — including media pipelines, rendering services, and image viewers (Github Advisory, OpenEXR Advisory).
A proof-of-concept exploit is publicly available via the official security advisory, with concrete, reproducible steps using a Docker-based environment to demonstrate heap memory leakage (OpenEXR Advisory). Feedly threat intelligence rates the PoC confidence as high, noting the advisory provides step-by-step reproduction instructions. The EPSS score is approximately 0.04% (0.000400), indicating a low current probability of active exploitation. There is no evidence of in-the-wild exploitation or CISA KEV catalog inclusion at this time (Github Advisory).
uncompressed_size declared in the file's header metadata.exr_uncompress_buffer() decompresses the truncated zlib stream, receives LIBDEFLATE_SHORT_OUTPUT, and incorrectly returns EXR_ERR_SUCCESS with outSize less than uncompressed_size.undo_pxr24_impl() function ignores outSize and reads the scratch buffer up to uncompressed_size, incorporating uninitialized heap memory into the decoded pixel data..exr files using PXR24 compression in directories processed by OpenEXR-based applications; output image files with anomalous pixel data patterns inconsistent with the expected image content.Upgrade OpenEXR to a patched version: 3.4.8 (for the 3.4.x branch), 3.3.9 (for the 3.3.x branch), or 3.2.7 (for the 3.2.x branch). The fix validates that outSize matches the expected packed payload size after decompression and rejects chunks where these values differ (Patch Commit, v3.4.8 Release). As a workaround where upgrading is not immediately feasible, restrict EXR file processing to trusted, internally generated sources and avoid processing externally supplied PXR24-compressed EXR files (Github Advisory).
The vulnerability was disclosed by the Academy Software Foundation (ACSF) through GitHub's security advisory system. The openSUSE security team issued a security announcement addressing the issue for their distributions (openSUSE Announcement). No significant broader media coverage or notable researcher commentary beyond the official advisory has been identified at this time.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
openexr
devel
openexr
focal (esm-apps)
openexr
jammy
openexr
jammy (esm-apps)
openexr
noble
openexr
noble (esm-apps)
openexr
questing
openexr
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."