cvedb.io
CVE-2025-48073
MEDIUM · CVSS 6.2
EPSS exploitation probability: 0%
Published 2025-07-31T21:15:28.340 · Last modified 2026-06-17T09:29:06.560

Summary

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.

Affected products

openexr — openexr

Does this affect you?

Add your gear to cvedb and we'll alert you only when openexr ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.