{"id":"CVE-2026-34544","summary":"OpenEXR: integer overflow to OOB write in uncompress_b44_impl()","details":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.","aliases":["GHSA-h762-rhv3-h25v","PYSEC-2026-2847"],"modified":"2026-09-18T14:02:29.483524Z","published":"2026-04-01T20:55:30.493Z","related":["openSUSE-SU-2026:10505-1"],"database_specific":{"cwe_ids":["CWE-190","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34544.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.8"},{"type":"ADVISORY","url":"https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-h762-rhv3-h25v"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34544.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34544"},{"type":"FIX","url":"https://github.com/AcademySoftwareFoundation/openexr/commit/35e7aa35e22c1975606be86e859f31cc1fc598ee"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/academysoftwarefoundation/openexr","events":[{"introduced":"456bf42dc2fddb647c0e9ab911656e5cf757fc36"},{"fixed":"f6f9cee0da36e8e806f7c9186f737db487782b69"},{"introduced":"c7d3eac70ccde2c4ed484c6638b83ba872f71464"},{"fixed":"8bb3562bd7bd833bd052224c596cb4aba94afb1b"},{"introduced":"20a65852895894434bea88613f6d29ac8e88bd6e"},{"fixed":"adbd2a588b47b1f6d02557571d8e36a91084da8a"},{"fixed":"35e7aa35e22c1975606be86e859f31cc1fc598ee"}],"database_specific":{"cpe":"cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.2.0"},{"fixed":"3.2.7"},{"introduced":"3.3.0"},{"fixed":"3.3.9"},{"introduced":"3.4.0"},{"fixed":"3.4.8"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v3.3.9-rc","v3.2.6-rc","v3.2.6","v3.3.8-rc","v3.3.8","v3.4.7","v3.4.7-rc","v3.4.6","v3.4.6-rc","v3.2.5-rc","v3.2.5","v3.3.7-rc4","v3.3.7","v3.4.5","v3.4.5-rc","v3.3.7-rc3","v3.3.7-rc2","v3.3.7-rc","v3.3.6","v3.4.4-rc2","v3.4.4","v3.4.4-rc","v3.4.3-rc3","v3.4.3","v3.3.6-rc4","v3.3.6-rc3","v3.4.3-rc2","v3.2.4-rc2","v3.2.4","v3.3.6-rc2","v3.4.3-rc","v3.3.6-rc","v3.3.5","v3.4.2-rc2","v3.4.2","v3.4.2-rc","v3.4.1-rc2","v3.4.1","v3.4.1-rc","v3.4.0","v3.3.5-rc3","v3.3.5-rc","v3.3.4-rc","v3.3.4","v3.3.3-rc1","v3.3.3","v3.3.3-rc","v3.3.2-rc4","v3.3.2","v3.3.2-rc3","v3.3.2-rc2","v3.3.2-rc","v3.3.1-rc","v3.3.1","v3.3.0-rc2","v3.3.0","v3.2.4-rc","v3.2.3-rc2","v3.2.3","v3.2.3-rc","v3.2.2","v3.2.2-rc2","v3.2.2-rc","v3.2.1-rc","v3.2.1","v3.2.0-rc4","v3.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34544.json","vanir_signatures_modified":"2026-09-18T14:02:29Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/academysoftwarefoundation/openexr/commit/35e7aa35e22c1975606be86e859f31cc1fc598ee","target":{"file":"src/lib/OpenEXRCore/internal_b44.c"},"deprecated":false,"digest":{"line_hashes":["276397591406414987157223138669390551343","207017963297339139629666808440499617952","258498797786942638680668736858319268893","315262617776304388131884812602531639480","127504814518261423286313544445133863221","39371125294579058207904839255938866702","133476267992572095507630736703855750443","320629989619655886061435680669864645031","251896877681848548285967733398324838646","151156264196910300547221049303026351707","120575723358568620194983621492769081261","212509365036623036242354796056745569891","127504814518261423286313544445133863221","39371125294579058207904839255938866702","49358004077028278978047835077116679765","135726513266582114988703839670503912280","73668656731463308536341558883887552683"],"threshold":0.9},"id":"CVE-2026-34544-416cc5a3","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"315159114857782705814262621327102255161","length":3153},"id":"CVE-2026-34544-4e916912","signature_type":"Function","signature_version":"v1","source":"https://github.com/academysoftwarefoundation/openexr/commit/35e7aa35e22c1975606be86e859f31cc1fc598ee","target":{"file":"src/lib/OpenEXRCore/internal_b44.c","function":"compress_b44_impl"}},{"deprecated":false,"digest":{"function_hash":"332192218539639116713203287700456517198","length":2673},"id":"CVE-2026-34544-95d32eda","signature_type":"Function","signature_version":"v1","source":"https://github.com/academysoftwarefoundation/openexr/commit/35e7aa35e22c1975606be86e859f31cc1fc598ee","target":{"file":"src/lib/OpenEXRCore/internal_b44.c","function":"uncompress_b44_impl"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}