Vulnerabilities & PatchesEmerging1 src
CVE-2026-59981 - OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow
CVE ID : CVE-2026-59981
Published : Aug. 25, 2026, 8:16 p. m.
• 55 minutes ago
Description : OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3. 2. 10, 3. 3. 0 through 3. 3. 12, and 3. 4. 0 through 3. 4. 13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin.
The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow. min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer.