Quang Luong discovered that OpenEXR incorrectly handled sample count
accumulation when processing deep scan line image files. An attacker could
possibly use this issue to cause OpenEXR to crash, resulting in a denial of
service, or execute arbitrary code. (CVE-2026-27622)
It was discovered that OpenEXR had an integer overflow in the PXR24
decoder. An attacker could possibly use this issue to cause OpenEXR to
crash, resulting in a denial of service, or execute arbitrary code.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-34380)
Quang Luong discovered that OpenEXR had a signed integer overflow in the
PIZ decoder. An attacker could possibly use this issue to cause OpenEXR to
crash, resulting in a denial of service, or execute arbitrary code. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-34588)
Intelligence View
⚡ tsecurity.de Intelligence
USN-8259-1: OpenEXR vulnerabilities
Quang Luong discovered that OpenEXR incorrectly handled sample count accumulation when processing deep scan line image files. An attacker could possibly use…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
BSI-Warnung (Deutschland)CVE-2026-27622
Red Hat Enterprise Linux (openexr): Schwachstelle ermöglicht Codeausführung und Dos12.04.2026CISA-SSVC-Triage (vulnrichment)CVE-2026-27622
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2026-03-04T16:06:34.211154Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com