MANAZYR NEWS

INDEPENDENT VISUAL NEWS

Front pageStandards
VFX pipeline security EVENT DATE · 3 MIN READ

OpenEXR patches IDManifest memory-exhaustion paths across three maintained branches

OpenEXR 3.4.15, 3.3.14 and 3.2.12 limit two memory-allocation problems in the optional IDManifest decoder path. The scope is narrower than all EXR reading, but exposed pipelines still need their dependency versions checked.

Typographic factual cover reading OpenEXR 3.4.15, IDManifest limits and three branches patched; no product image
MANAZYR factual cover based on the official OpenEXR release scope; no synthetic product image. MANAZYR factual cover.
01

What happened

The OpenEXR project released 3.4.15, 3.3.14 and 3.2.12 on August 21. The release notes say two issues could cause excessive memory allocation when parsing corrupt or malicious IDManifest data. CVE identifiers had been requested but were not yet listed.

The affected behaviour is limited to code that decodes the IDManifest attribute; the project says other OpenEXR code is not affected even when an image contains that attribute. Version 3.4.15 also carries Windows export and compiler-warning fixes.

02

Why it matters

This is an availability and resource-exhaustion problem in a defined decoder path, not evidence of universal EXR compromise or remote code execution. Studios should map the library through renderers, ingest tools and asset services before deciding where untrusted files can reach the vulnerable code.
03

What we're watching

We are watching CVE assignment and downstream packages in VFX, DCC and render-farm tooling. Teams that do not decode IDManifest are outside the stated affected path, but should still verify rather than assume their build configuration.

PRIMARY / ORIGINAL

Source trail

Original material used for this MANAZYR report.
  1. 01OpenEXR — Version 3.4.15 release
  2. 02OpenEXR — Security policy