Allocation of Resources Without Limits or Throttling
CVE-2025-48074
Summary
OpenEXR provides both the specification and reference implementation for the EXR image file format, widely used in the motion picture industry. In versions 3.2.3 through 3.3.2 are affected by a vulnerability where applications trust unvalidated "dataWindow" size values from file headers. This can lead to excessive memory allocation and performance degradation when processing maliciously crafted files. This is fixed in version 3.3.3.
- LOW
- LOCAL
- NONE
- UNCHANGED
- REQUIRED
- NONE
- NONE
- HIGH
CWE-770 - Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
References
Advisory Timeline
- Published