cbcvebase.
CVE-2025-64181
published 2025-11-10

CVE-2025-64181: OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.37%
29.6th percentile
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
academysoftwarefoundationopenexr
academysoftwarefoundationopenexr
debianopenexr< openexr 3.4.6+ds-1 (forky)openexr 3.4.6+ds-1 (forky)
openexropenexr>= 0 < 3.4.6+ds-13.4.6+ds-1
openexropenexr>= 3.3.0 < 3.3.63.3.6
openexropenexr>= 3.3.0 < 3.3.63.3.6
openexropenexr>= 3.4.0 < 3.4.33.4.3
openexropenexr>= 3.4.0 < 3.4.33.4.3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.02.0LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv2.0LOW
vendor_debian2.0LOW
vendor_redhat2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.