{"id":"CVE-2026-65979","summary":"OpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header length (PLEN)","details":"OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the HTJ2K decoder parses a header-length field (PLEN) from a chunk's compressed data but never checks that this value fits within the available buffer before using it. When decoding, it advances the codestream pointer by the attacker-supplied header size and passes the resulting offset and remaining length to the OpenJPH memory-input path, so a crafted value pushes the pointer past the end of the buffer and causes an out-of-bounds read. Because this field comes straight from attacker-controlled EXR chunk data, the flaw is reachable during normal decoding of an untrusted file. This issue is fixed in version 3.4.13.","aliases":["GHSA-3j9c-j7c9-x293"],"modified":"2026-08-27T11:47:40.653477349Z","published":"2026-08-25T18:58:25.871Z","related":["openSUSE-SU-2026:11612-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125","CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65979.json"},"references":[{"type":"WEB","url":"https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.13"},{"type":"ADVISORY","url":"https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3j9c-j7c9-x293"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65979.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65979"},{"type":"FIX","url":"https://github.com/AcademySoftwareFoundation/openexr/commit/c7af2d233b7b2a4452c11f26cf47584cc2b35721"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/academysoftwarefoundation/openexr","events":[{"introduced":"20a65852895894434bea88613f6d29ac8e88bd6e"},{"fixed":"c1194b2cb23a1bdf76fe5e756b22e8436b9a98c9"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"3.4.0"},{"fixed":"3.4.13"}]}}],"versions":["v3.4.13-rc2","v3.4.13-rc","v3.4.12","v3.4.12-rc2","v3.4.11-rc3","v3.4.11","v3.4.11-rc2","v3.4.11-rc","v3.4.10-rc","v3.4.10","v3.4.9","v3.4.9-rc","v3.4.8-rc","v3.4.8","v3.4.7","v3.4.7-rc","v3.4.6","v3.4.6-rc","v3.4.5","v3.4.5-rc","v3.4.4-rc2","v3.4.4","v3.4.4-rc","v3.4.3-rc3","v3.4.3","v3.4.3-rc2","v3.4.3-rc","v3.4.2-rc2","v3.4.2","v3.4.2-rc","v3.4.1-rc2","v3.4.1","v3.4.1-rc","v3.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65979.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}