#VU125323 Heap-based buffer overflow in OpenEXR - CVE-2025-48071
Published: April 8, 2026
OpenEXR
OpenEXR
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in the undo_zip_impl function and deep scanline ZIP reconstruction logic when parsing a crafted ZIPS-packed deep scan-line EXR file with a forged chunk header. A remote attacker can supply a specially crafted EXR file to execute arbitrary code.
User interaction is required to open or process a crafted EXR file.