Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-146

JLSEC-2026-146

JLSEC Published
Modified
Affected Packages
OpenEXR_jll >= 3.1.4+0, < 3.4.8+0
Aliases / Upstream
CVE-2026-34544

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exrdecodingrun(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.

References