OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-23375 OpenEXR Out-Of-Memory via Unbounded File Header Values
Github GHSA Github GHSA GHSA-x22w-82jp-8rvf OpenEXR Out-Of-Memory via Unbounded File Header Values
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 14 Aug 2025 04:30:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:openexr:openexr:3.3.2:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Tue, 12 Aug 2025 21:15:00 +0900

Type Values Removed Values Added
First Time appeared Openexr
Openexr openexr
Vendors & Products Openexr
Openexr openexr

Sat, 02 Aug 2025 09:15:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

threat_severity

Low


Sat, 02 Aug 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 02 Aug 2025 01:45:00 +0900

Type Values Removed Values Added
Description OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.
Title OpenEXR's Unbounded File Header Values can Lead to Out-Of-Memory Errors
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-08-01T17:09:00.696Z

Reserved: 2025-05-15T16:06:40.942Z

Link: CVE-2025-48074

cve-icon Vulnrichment

Updated: 2025-08-01T17:08:51.656Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-01T17:15:52.193

Modified: 2025-08-13T19:18:13.987

Link: CVE-2025-48074

cve-icon Redhat

Severity : Low

Publid Date: 2025-08-01T16:32:54Z

Links: CVE-2025-48074 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-08-12T21:05:49Z

Weaknesses