CVE-2026-55371: OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length
OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore function exrattrsetbytes(). The public setter validates the top-level exrattrbytest value pointer but does not verify that the nested typehint pointer is non-NULL when hintlength is greater than zero. When a caller supplies a positive hintlength together with a NULL typehint, exrattrbytescreate() allocates a destination type-hint buffer and then copies from the NULL source pointer, causing a deterministic crash. The flaw is reachable through the public OpenEXRCore C API and results in a denial of service. The issue is fixed in version 3.4.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenEXR (OpenEXRCore)to a version that resolves this vulnerability.Fixed in 3.4.13
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using the public OpenEXRCore C API in OpenEXR versions 3.4.0 through 3.4.12 are exposed if they call exr_attr_set_bytes() with attacker-controlled or otherwise invalid attribute-byte parameters.
What input is required to trigger the crash?
A caller must supply an exr_attr_bytes_t value with a positive hint_length while its nested type_hint pointer is NULL. The function then attempts to copy from the NULL pointer, causing a deterministic crash.
Does exploitation require authentication, user interaction, or network access?
The provided CVSS vector indicates local attack vector, no privileges required, and no user interaction. The described impact is denial of service through a crash.
What should teams do if they cannot update immediately?
Avoid calling exr_attr_set_bytes() with a positive hint_length unless type_hint points to a valid buffer. Validate this pointer-and-length relationship in application code before invoking the OpenEXRCore API.
Which version fixes the issue?
OpenEXR 3.4.13 fixes this issue. Versions 3.4.0 through 3.4.12 are affected.