{"id":"JLSEC-2026-644","summary":"When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of...","details":"When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate the output data.\n\nWe read `rle_raw_size` from the input file at [0], we decompress and decode into the buffer `td-\u003erle_raw_data` of size `rle_raw_size` at [1], and then at [2] we will access entries in this buffer up to `(td-\u003exsize - 1) * (td-\u003eysize - 1) + rle_raw_size / 2`, which may exceed `rle_raw_size`.\n\nWe recommend upgrading to version 8.0 or beyond.","modified":"2026-07-25T18:25:20.397833172Z","published":"2026-06-26T20:24:16.337Z","upstream":["CVE-2025-59731","GHSA-p7r5-qh99-qchm","EUVD-2025-32181"],"database_specific":{"sources":[{"database_specific":{"status":"Deferred"},"id":"CVE-2025-59731","imported":"2026-07-17T22:18:54.885Z","modified":"2026-06-17T09:46:36.573Z","published":"2025-10-06T08:15:34.770Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-59731","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59731"},{"imported":"2026-07-17T22:18:55.082Z","modified":"2025-10-19T15:31:16Z","published":"2025-10-06T09:30:20Z","url":"https://api.github.com/advisories/GHSA-p7r5-qh99-qchm","html_url":"https://github.com/advisories/GHSA-p7r5-qh99-qchm","id":"GHSA-p7r5-qh99-qchm"},{"modified":"2026-02-26T17:48:18Z","published":"2025-10-06T08:09:23Z","url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-32181","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-32181","id":"EUVD-2025-32181","imported":"2026-07-17T22:18:55.601Z"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"https://b.corp.google.com/issues/436510153"},{"type":"WEB","url":"https://github.com/advisories/GHSA-p7r5-qh99-qchm"},{"type":"WEB","url":"https://issuetracker.google.com/436510153"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59731"}],"affected":[{"package":{"name":"FFMPEG_jll","ecosystem":"Julia","purl":"pkg:julia/FFMPEG_jll?uuid=b22a6f82-2f65-5046-a5b2-351ab43fb4e5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.1.1+0"},{"fixed":"8.0.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-644.json"}},{"package":{"name":"FFplay_jll","ecosystem":"Julia","purl":"pkg:julia/FFplay_jll?uuid=c4dce911-e170-5107-8314-c7bdc6785395"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.1.1+0"},{"fixed":"8.1.2+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-644.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}