# CVE-2026-34379

## Summary

- **CVE ID:** CVE-2026-34379
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H)
- **CWE:** CWE-704, CWE-787, CWE-843
- **Published:** Apr 6, 2026
- **Last Modified:** Jul 15, 2026

## Description

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

## Affected Products

- AcademySoftwareFoundation — openexr (>= 3.2.0, < 3.2.7)
- AcademySoftwareFoundation — openexr (>= 3.3.0, < 3.3.9)
- AcademySoftwareFoundation — openexr (>= 3.4.0, < 3.4.9)

## References

- [CNA](https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-w88v-vqhq-5p24)
- [CNA](https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.2.7)
- [CNA](https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.3.9)
- [CNA](https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.9)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-34379)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2455402)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34379.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.28%
- **EPSS Percentile:** 20.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._