Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-59732

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-787 Escritura fuera de límites
Fecha de publicación:
06/10/2025
Última modificación:
19/10/2025

Descripción

*** Pendiente de traducción *** When decoding an OpenEXR file that uses DWAA or DWAB compression, there&amp;#39;s an implicit assumption that the height and width are divisible by 8.<br /> <br /> If the height or width of the image is not divisible by 8, the copy loops at [0] and [1] will continue to write until the next multiple of 8.<br /> <br /> The buffer td-&gt;uncompressed_data is allocated in decode_block based on the precise height and width of the image, so the "rounded-up" multiple of 8 in the copy loop can exceed the buffer bounds, and the write block starting at [2] can corrupt following heap memory.<br /> <br /> <br /> <br /> We recommend upgrading to version 8.0 or beyond.

Referencias a soluciones, herramientas e información