CVE Vulnerabilities

CVE-2026-34543

Use of Uninitialized Resource

Published: Apr 01, 2026 | Modified: Apr 07, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
OpenexrOpenexr3.2.0 (including)3.2.7 (excluding)
OpenexrOpenexr3.3.0 (including)3.3.9 (excluding)
OpenexrOpenexr3.4.0 (including)3.4.8 (excluding)
OpenexrUbuntudevel*
OpenexrUbuntuupstream*

Potential Mitigations

References