Skip to content
VulniPulse
High7.1Red Hat Linux

High [CVE-2026-45696] Denial of Service and potential information disclosure via crafted EXR file

This high-severity Red Hat Linux advisory covers CVE-2026-45696 affecting Red Hat Enterprise Linux 6.

CVE-2026-45696 Published Jun 18, 2026Updated by vendor Jun 18, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ.

The ht_undo_imp function copies decoded pixels out of a per-line OpenJPH buffer using the EXR channel's declared width as the iteration count.

The codestream embedded in the EXR chunk can declare different (smaller) tile/line dimensions than the EXR header advertises, but ht_undo_impl() does not validate this — it pulls width 32-bit samples from cur_line->i32[] without checking the OpenJPH line buffer's actual length.

A crafted EXR file produces a 4-byte heap-buffer-overflow READ immediately after a buffer allocated by ojph::local::codestream::finalize_alloc().

The bug is reachable through the standard scanline-decode entry point used by every consumer of exr_decoding_run/Imf::checkOpenEXRFile, including thumbnailers, asset pipelines, and the exrcheck utility — i.e. any application that opens untrusted EXR files. The result is a deterministic crash (DoS) and potential adjacent-heap leak.

This issue has been fixed in version 3.4.12. If an application opens a maliciously crafted EXR image file, it triggers a memory error.

Affected product named by the advisory: Red Hat Enterprise Linux 6.

Affected versions
  • 3.4.0
  • 3.4.11

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Fixed versions
  • 3.4.12

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To minimize risk, avoid opening or processing EXR image files from untrusted or unknown sources. For environments that must process external files, run the handling applications within a sandboxed environment to restrict their privileges and limit the damage a potential exploit can cause.

Official advisory · high-confidence parse· fetched 16 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.