Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
ECHO-fd63-872c-58aa
See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-fd63-872c-58aa.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-fd63-872c-58aa
Upstream
CVE-2026-34544
Withdrawn
2026-06-01T13:30:03Z
Published
2026-06-01T07:39:17Z
Modified
2026-09-15T03:33:45Z
Summary
Out-of-bounds write in B44/B44A via exr_decoding_run(). The vulnerable code path through the new C core decoding API was introduced in 3.4.0 and does not exist in 3.1.x.
Details
References
https://advisory.echohq.com/cve/CVE-2026-34544
Affected packages
Echo
/
openexr
Package
Name
openexr
Purl
pkg:deb/echo/openexr
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.1.13-2
Database specific
source
"https://advisory.echohq.com/osv/ECHO-fd63-872c-58aa.json"
ECHO-fd63-872c-58aa - OSV