{"id":"ECHO-d0fa-76ab-4b21","summary":"Heap-buffer-overflow READ in ht_undo_impl() via codestream/channel\nwidth mismatch in the HTJ2K decoder. HTJ2K support (OpenEXRCore\ninternal_ht.cpp / ht_undo_impl) was added in 3.4.0; affected range\nis 3.4.0-3.4.11. The codec does not exist in 3.1.x, so 3.1.13 is\nnot affected (Debian reports only a fixed_version, not the affected\nrange).\n","modified":"2026-09-15T03:33:45.962211669Z","published":"2026-06-21T16:44:41.890Z","withdrawn":"2026-06-24T18:00:04.378Z","upstream":["CVE-2026-45696"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-45696"}],"affected":[{"package":{"name":"openexr","ecosystem":"Echo","purl":"pkg:deb/echo/openexr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.13-2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-d0fa-76ab-4b21.json"}}],"schema_version":"1.9.0"}