OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27622.json"
}{
"extracted_events": [
{
"introduced": "2.3.0"
},
{
"fixed": "3.2.6"
},
{
"introduced": "3.3.0"
},
{
"fixed": "3.3.8"
},
{
"introduced": "3.4.0"
},
{
"fixed": "3.4.6"
}
],
"source": "AFFECTED_FIELD"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27622.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"239338313904543462456885454604527003099",
"109654351193261023483294361034554114820"
],
"threshold": 0.9
},
"id": "CVE-2026-27622-8f60c111",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/academysoftwarefoundation/openexr/commit/3fad448f2c98c70a2f6403566a664e32bbe770f8",
"target": {
"file": "src/lib/OpenEXRCore/openexr_version.h"
}
}
]
"2026-09-18T14:02:28Z"