{"id":"CVE-2026-88384","published":"2026-09-24T17:17:07.907","lastModified":"2026-09-24T21:08:22.573","description":"OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to zero causes the parser to create an opaque attribute with a NULL packed_data pointer. The OpaqueAttribute constructor passes the NULL pointer to memcpy() without validating the zero-size condition, resulting in undefined behavior and process termination, leading to denial of service.","cvssScore":5.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwes":["CWE-476"],"vendors":[],"products":[],"references":[{"url":"https://github.com/AcademySoftwareFoundation/openexr/issues/2612","tags":[]},{"url":"https://github.com/AcademySoftwareFoundation/openexr/pull/2615","tags":[]},{"url":"https://github.com/AcademySoftwareFoundation/openexr/pull/2615/changes/70ddecfe82d2566f3776b8ed923939afd47baca2","tags":[]},{"url":"https://github.com/AcademySoftwareFoundation/openexr/issues/2612","tags":[]}],"exploitRefs":[{"url":"https://github.com/AcademySoftwareFoundation/openexr/issues/2612","tags":[]},{"url":"https://github.com/AcademySoftwareFoundation/openexr/pull/2615","tags":[]},{"url":"https://github.com/AcademySoftwareFoundation/openexr/pull/2615/changes/70ddecfe82d2566f3776b8ed923939afd47baca2","tags":[]},{"url":"https://github.com/AcademySoftwareFoundation/openexr/issues/2612","tags":[]}],"hasPoc":true,"ai":null}