ECHO-f43e-2c25-b994

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-f43e-2c25-b994.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-f43e-2c25-b994
Upstream
Withdrawn
2026-06-01T13:30:03Z
Published
2026-06-01T07:39:17Z
Modified
2026-09-15T03:33:42Z
Summary
Excessive memory allocation via unvalidated dataWindow size values. The vulnerability is specific to 3.3.x+ code paths. In 3.1.13, the equivalent code uses uiMult() which has built-in overflow checking, and the chunkTableValid() API used in the fix does not exist.
Details
References

Affected packages

Echo / openexr

Package

Name
openexr
Purl
pkg:deb/echo/openexr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.13-2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-f43e-2c25-b994.json"