CVE-2026-34543: Openexr Bounds Check Capacity Mismatch

Bounds checking against the expected uncompressed capacity rather than the actual decompressed payload length may lead to out-of-bounds reads into uninitialized memory.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-34543-openexr-bounds-check-capacity-mismatch --engine opengrep

Description

Bounds checking against the expected uncompressed capacity rather than the actual decompressed payload length may lead to out-of-bounds reads into uninitialized memory.