A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all memory accessible to the application. The highest threat from this vulnerability is to system availability.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "10.0"
}
]
}
]
}{
"cpe": "cpe:2.3:a:openexr:openexr:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.5.7"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-20298.json"
"2026-04-12T01:00:40Z"
[
{
"deprecated": false,
"signature_type": "Line",
"digest": {
"line_hashes": [
"337182622941885860691948893909499588135",
"323662791025237067706865570695215691721",
"262227886135352975191095936665666742560",
"102441096919337918920502902234704070284"
],
"threshold": 0.9
},
"target": {
"file": "OpenEXR/IlmImf/ImfB44Compressor.cpp"
},
"source": "https://github.com/academysoftwarefoundation/openexr/commit/85fd638ae0d5fa132434f4cbf32590261c1dba97",
"signature_version": "v1",
"id": "CVE-2021-20298-7d322475"
},
{
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "73840588326705174605545363839552404531",
"length": 1483.0
},
"target": {
"file": "OpenEXR/IlmImf/ImfB44Compressor.cpp",
"function": "B44Compressor::B44Compressor"
},
"source": "https://github.com/academysoftwarefoundation/openexr/commit/85fd638ae0d5fa132434f4cbf32590261c1dba97",
"signature_version": "v1",
"id": "CVE-2021-20298-a5a84c0a"
}
]