A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openexr | Aug 6, 2021 | Aug 6, 2021 |
| Huawei Euleros 2_0_sp8 | — | — | Sep 24, 2021 | Sep 24, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 16, 2022 |
| Suse | — | Upgrade libilmimf-2_2-23Upgrade openexr-docUpgrade libilmimfutil-2_2-23Upgrade libilmimf-2_2-23-32bitUpgrade libilmimf-imf_2_1-21-32bitUpgrade libilmimfutil-2_2-23-32bitUpgrade libilmimf-imf_2_1-21Upgrade openexr-develUpgrade openexr | Aug 21, 2021 | Aug 20, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub