A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openexr | Aug 6, 2021 | Aug 6, 2021 |
| Huawei Euleros 2_0_sp8 | — | — | Sep 24, 2021 | Sep 24, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 16, 2022 |
| Suse | — | Upgrade libilmimf-imf_2_1-21-32bitUpgrade libilmimfutil-2_2-23-32bitUpgrade openexr-develUpgrade libilmimf-imf_2_1-21Upgrade openexrUpgrade libilmimfutil-2_2-23Upgrade openexr-docUpgrade libilmimf-2_2-23Upgrade libilmimf-2_2-23-32bit | Aug 21, 2021 | Aug 20, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub