CVE-2026-45696
CVE-2026-45696: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.1
High [CVE-2026-45696] Denial of Service and potential information disclosure via crafted EXR file
CVE-2026-45696Source published Source updated
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.11, the HTJ2K (High-Throughput JPEG 2000) decoder, ht_undo_impl() in OpenEXRCore is vulnerable to a heap-buffer-overflow READ. The ht_undo_imp function copies decoded pixels out of a per-line OpenJPH buffer using the EXR channel's declared width as the iteration count. The codestream embedded in the EXR chunk can declare different (smaller) tile/line dimensions than the EXR header advertises, but ht_undo_impl() does not validate this — it pulls width 32-bit samples from cur_line->i32[] without checking the OpenJPH line buffer's actual length. A crafted EXR file produces a 4-byte heap-buffer-overflow READ immediately after a buffer…
- Affected products in this advisory
- Red Hat Enterprise Linux 6
- Red Hat package: openexr
- Source-reported affected versions
- 3.4.0
- 3.4.11
- Source-reported fixed versions
- 3.4.12
- Mitigation guidance
- To minimize risk, avoid opening or processing EXR image files from untrusted or unknown sources. For environments that must process external files, run the handling applications within a sandboxed environment to restrict their privileges and limit the damage a potential exploit can cause.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.