OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.
History

Mon, 04 Aug 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Openexr
Openexr openexr
Vendors & Products Openexr
Openexr openexr

Fri, 01 Aug 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

threat_severity

Low


Thu, 31 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 20:30:00 +0000

Type Values Removed Values Added
Description OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.
Title OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-31T20:25:51.545Z

Updated: 2025-07-31T20:36:41.060Z

Reserved: 2025-05-15T16:06:40.942Z

Link: CVE-2025-48073

cve-icon Vulnrichment

Updated: 2025-07-31T20:36:34.845Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-31T21:15:28.340

Modified: 2025-08-04T15:06:36.623

Link: CVE-2025-48073

cve-icon Redhat

Severity : Low

Publid Date: 2025-07-31T20:25:51Z

Links: CVE-2025-48073 - Bugzilla