CVE-2026-34544: CVE-2026-34544: Signed Integer Overflow and Out-of-Bounds Write in OpenEXRCore B44/B44A Compression
CVE-2026-34544: Signed Integer Overflow and Out-of-Bounds Write in OpenEXRCore B44/B44A Compression Vulnerability ID: CVE-2026-34544 CVSS Score: 8.4 Published: 2026-04-03 A high-severity signed int...

Source: DEV Community
CVE-2026-34544: Signed Integer Overflow and Out-of-Bounds Write in OpenEXRCore B44/B44A Compression Vulnerability ID: CVE-2026-34544 CVSS Score: 8.4 Published: 2026-04-03 A high-severity signed integer overflow vulnerability in the OpenEXR library's B44 and B44A compression modules allows for out-of-bounds memory writes. This flaw can be triggered during the encoding or decoding of maliciously crafted EXR files, potentially resulting in denial of service or arbitrary code execution. TL;DR OpenEXR versions 3.4.0 through 3.4.7 suffer from an integer overflow in internal_b44.c that leads to an out-of-bounds write during B44/B44A image compression handling. Upgrading to version 3.4.8 resolves the issue by enforcing 64-bit bounds calculations. Technical Details CWE ID: CWE-190 Attack Vector: Local / User Interaction Required CVSS v4.0: 8.4 EPSS Score: 0.00013 Impact: Denial of Service / Potential Remote Code Execution Exploit Status: None CISA KEV: Not Listed Affected Systems Applications d