Two vulnerabilities were disclosed in OpenEXRCore affecting image compression and decompression paths for EXR files. CVE-2026-34543 impacts PXR24 decompression: exr_uncompress_buffer in compression.c can treat libdeflate's short output condition as a successful decode, while undo_pxr24_impl in internal_pxr24.c trusts the uncompressed_size value from an untrusted EXR header instead of the actual decompressed byte count. A crafted truncated file can cause reconstruction logic to read beyond initialized scratch_data and include uninitialized heap contents in image output, creating an information disclosure risk.
A second flaw, CVE-2026-34544, affects B44/B44A compression and decompression in internal_b44.c. The uncompress_b44_impl and compress_b44_impl functions use 32-bit signed integers for row-pointer offset calculations, and multiplying large image dimensions can overflow INT_MAX. The resulting negative offsets can point outside the allocated scratch buffer and trigger out-of-bounds writes, creating a heap memory corruption condition that could let attackers influence adjacent allocations depending on process layout.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
OpenEXR disclosed CVE-2026-34589, a heap out-of-bounds write in the DWA lossy decoder caused by signed 32-bit arithmetic overflow when building per-component block pointers for large image widths. The issue affects versions 3.2.0 through before 3.2.7 and earlier supported 3.3 and 3.4 releases, and was fixed in versions 3.2.7, 3.3.9, and 3.4.9.
A second OpenEXRCore vulnerability was disclosed affecting B44 and B44A compression and decompression, where signed integer overflow in row-pointer offset calculations can trigger out-of-bounds writes in the scratch buffer.
A vulnerability in OpenEXR was disclosed in which truncated compressed data can be misinterpreted as successfully decompressed, causing the PXR24 decoder to read uninitialized heap memory and leak it through malformed image output.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.