Vulnerability Description
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openexr | Openexr | >= 3.2.0, < 3.2.7 |
Related Weaknesses (CWE)
References
- https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7ProductRelease Notes
- https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9ProductRelease Notes
- https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9ProductRelease Notes
- https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-w8ExploitVendor Advisory
FAQ
What is CVE-2026-34379?
CVE-2026-34379 is a vulnerability with a CVSS score of 7.1 (HIGH). OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misalig...
How severe is CVE-2026-34379?
CVE-2026-34379 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-34379?
Check the references section above for vendor advisories and patch information. Affected products include: Openexr Openexr.