A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openexr | Aug 6, 2021 | Aug 6, 2021 |
| Huawei Euleros 2_0_sp8 | — | — | Sep 24, 2021 | Sep 24, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 16, 2022 |
| Suse | — | Upgrade openexrUpgrade libilmimf-imf_2_1-21Upgrade openexr-develUpgrade libilmimf-imf_2_1-21-32bitUpgrade libilmimfutil-2_2-23-32bitUpgrade openexr-docUpgrade libilmimfutil-2_2-23Upgrade libilmimf-2_2-23-32bitUpgrade libilmimf-2_2-23 | Aug 21, 2021 | Aug 20, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub