← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 25, 2026 · 20:17via CVEFeed

CVE-2026-68513 - OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel name collision

Brief

CVE ID : CVE-2026-68513

Published : Aug. 25, 2026, 8:17 p. m.

  • 55 minutes ago

Description : OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.

  • 0 through 3.
  • 12 and 3.
  • 0 through 3.
  • 13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels.

When separate_channels=false, PyOpenEXR maps each physical channel name through channelNameToRGBA() and coalesces the results into a shared RGB array. A crafted flat scanline EXR that contains both a literal channel such as left and prefixed channels such as left. R, left. G, and left.

B causes these names to collide, so the wrapper reuses an undersized two-dimensional NumPy array for the coalesced RGB slices and writes out of bounds when OpenEXR. File(path) decodes the pixels.

Read more on CVEFeed