CVE-2026-55371: OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positive hint_length

Published Aug 25, 2026
·
Updated

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore function exrattrsetbytes(). The public setter validates the top-level exrattrbytest value pointer but does not verify that the nested typehint pointer is non-NULL when hintlength is greater than zero. When a caller supplies a positive hintlength together with a NULL typehint, exrattrbytescreate() allocates a destination type-hint buffer and then copies from the NULL source pointer, causing a deterministic crash. The flaw is reachable through the public OpenEXRCore C API and results in a denial of service. The issue is fixed in version 3.4.13.

Affected Software

2 affected components
OpenEXR OpenEXR>=3.4.0<=3.4.12
OpenEXR OpenEXRCore=3.4.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenEXR (OpenEXRCore) to a version that resolves this vulnerability.

    Fixed in 3.4.13

Event History

Aug 25, 2026
CVE Published
via MITRE·12:31 AM
Data Sourced
via MITRE·12:31 AM
DescriptionWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using the public OpenEXRCore C API in OpenEXR versions 3.4.0 through 3.4.12 are exposed if they call exr_attr_set_bytes() with attacker-controlled or otherwise invalid attribute-byte parameters.

2

What input is required to trigger the crash?

A caller must supply an exr_attr_bytes_t value with a positive hint_length while its nested type_hint pointer is NULL. The function then attempts to copy from the NULL pointer, causing a deterministic crash.

3

Does exploitation require authentication, user interaction, or network access?

The provided CVSS vector indicates local attack vector, no privileges required, and no user interaction. The described impact is denial of service through a crash.

4

What should teams do if they cannot update immediately?

Avoid calling exr_attr_set_bytes() with a positive hint_length unless type_hint points to a valid buffer. Validate this pointer-and-length relationship in application code before invoking the OpenEXRCore API.

5

Which version fixes the issue?

OpenEXR 3.4.13 fixes this issue. Versions 3.4.0 through 3.4.12 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203