[From nobody Sat Aug 22 12:07:06 2026
Received: (at submit) by bugs.debian.org; 22 Apr 2026 15:51:52 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.9 required=4.0 tests=BAYES_00, FOURLA, MD5_SHA1_SUM,
 SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 79; hammy, 150; neutral, 157; spammy,
 0. spammytokens:
 hammytokens:0.000-+--UD:security-tracker.debian.org, 
 0.000-+--security-tracker.debian.org,
 0.000-+--securitytrackerdebianorg, 0.000-+--H*r:jmm, 0.000-+--size_t
Return-path: &lt;jmm@inutil.org&gt;
Received: from inutil.org ([51.38.114.215]:33572 helo=vps-b7ad3695.vps.ovh.net)
 by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;jmm@inutil.org&gt;) id 1wFZri-00APbQ-2O
 for submit@bugs.debian.org; Wed, 22 Apr 2026 15:51:52 +0000
Received: from soju.westfalen.local (p548dc5fc.dip0.t-ipconnect.de
 [84.141.197.252])
 by vps-b7ad3695.vps.ovh.net (Postfix) with ESMTPSA id C4A50164
 for &lt;submit@bugs.debian.org&gt;; Wed, 22 Apr 2026 15:51:47 +0000 (UTC)
Received: from jmm by soju.westfalen.local with local (Exim 4.99.1)
 (envelope-from &lt;jmm@soju.westfalen.local&gt;) id 1wFZrb-00000002pVW-1cjx
 for submit@bugs.debian.org; Wed, 22 Apr 2026 17:51:43 +0200
Date: Wed, 22 Apr 2026 17:51:43 +0200
To: submit@bugs.debian.org
Subject: openexr: CVE-2026-40250 CVE-2026-40244 CVE-2026-39886
Message-ID: &lt;aejuj1pmAul7EkR1@pisco.westfalen.local&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
From: =?UTF-8?Q?Moritz_M=C3=BChlenhoff?= &lt;jmm@inutil.org&gt;
Delivered-To: submit@bugs.debian.org

Source: openexr
X-Debbugs-CC: team@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerabilities were published for openexr.

CVE-2026-40250[0]:
| OpenEXR provides the specification and reference implementation of
| the EXR file format, an image storage format for the motion picture
| industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and
| 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs
| `chan-&gt;width * chan-&gt;bytes_per_element` in `int32` arithmetic
| without a `(size_t)` cast. This is the same overflow pattern fixed
| in other decoders by CVE-2026-34589/34588/34544, but this line was
| missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that
| addresses `internal_dwa_compressor.h:1040`.

https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m5qw-23x2-6phj
https://github.com/AcademySoftwareFoundation/openexr/pull/2346
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/416fecf71241c097d52da5b219d36afd94800e69 (main)
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/42d394a7b761325a3df7c2d57f9dfd905629ca4f (v3.4.10-rc)
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/a41f0d19841469148aabf7e1e056fab9f1c3c4f0 (v3.2.8-rc)
 

CVE-2026-40244[1]:
| OpenEXR provides the specification and reference implementation of
| the EXR file format, an image storage format for the motion picture
| industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and
| 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1722` performs
| `curc-&gt;width * curc-&gt;height` in `int32` arithmetic without a
| `(size_t)` cast. This is the same overflow pattern fixed in other
| locations by the recent CVE-2026-34589 batch, but this line was
| missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that
| addresses `internal_dwa_compressor.h:1722`.

https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m5qw-23x2-6phj
https://github.com/AcademySoftwareFoundation/openexr/pull/2346
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/416fecf71241c097d52da5b219d36afd94800e69 (main)
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/42d394a7b761325a3df7c2d57f9dfd905629ca4f (v3.4.10-rc)
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/a41f0d19841469148aabf7e1e056fab9f1c3c4f0 (v3.2.8-rc)


CVE-2026-39886[2]:
| OpenEXR provides the specification and reference implementation of
| the EXR file format, an image storage format for the motion picture
| industry. Versions 3.4.0 through 3.4.9 have a signed integer
| overflow vulnerability in OpenEXR's HTJ2K (High-Throughput JPEG
| 2000) decompression path. The `ht_undo_impl()` function in
| `src/lib/OpenEXRCore/internal_ht.cpp` accumulates a bytes-per-line
| value (`bpl`) using a 32-bit signed integer with no overflow guard.
| A crafted EXR file with 16,385 FLOAT channels at the HTJ2K maximum
| width of 32,767 causes `bpl` to overflow `INT_MAX`, producing
| undefined behavior confirmed by UBSan. On an allocator-permissive
| host where the required ~64 GB allocation succeeds, the wrapped
| negative `bpl` value would subsequently be used as a per-scanline
| pointer advance, which would produce a heap out-of-bounds write. On
| a memory-constrained host, the allocation fails before
| `ht_undo_impl()` is entered. This is the second distinct integer
| overflow in `ht_undo_impl()`. CVE-2026-34545 addressed a different
| overflow in the same function — the `int16_t p` pixel-loop counter
| at line ~302 that overflows when iterating over channels whose
| `width` exceeds 32,767. The CVE-2026-34545 fix did not touch the
| `int bpl` accumulator at line 211, which is the subject of this
| advisory. The `bpl` accumulator was also not addressed by any of the
| 8 advisories in the 2026-04-05 v3.4.9 release batch. This finding is
| structurally identical to CVE-2026-34588 (PIZ `wcount*nx` overflow
| in `internal_piz.c`) and should be remediated with the same pattern.
| The CVE-2026-34588 fix did not touch `internal_ht.cpp`. Version
| 3.4.10 contains a remediation that addresses the vulnerability in
| `internal_ht.cpp`.

https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-r3mr-mx8q-jcw5
https://github.com/AcademySoftwareFoundation/openexr/pull/2345
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/15fd269f7ecb291b0c4a31be695b5a2e6b566dc0 (main)
Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/1577f226fb6644b7b63908af58c031bf3fd11649 (v3.4.10-rc)


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-40250
    https://www.cve.org/CVERecord?id=CVE-2026-40250
[1] https://security-tracker.debian.org/tracker/CVE-2026-40244
    https://www.cve.org/CVERecord?id=CVE-2026-40244
[2] https://security-tracker.debian.org/tracker/CVE-2026-39886
    https://www.cve.org/CVERecord?id=CVE-2026-39886

Please adjust the affected versions in the BTS as needed.
]