CVE-2025-64182·Python vulnerability
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.2.0 through 3.2.4, 3.3.0 through 3.3.5, and 3.4.0 through 3.4.2, a memory safety bug in the legacy OpenEXR Python adapter (the deprecated OpenEXR.InputFile wrapper) allow crashes and likely code execution when opening attacker-controlled EXR files or when passing crafted Python objects. Integer overflow and unchecked allocation in InputFile.channel() and InputFile.channels() can lead to heap overflow (32 bit) or a NULL deref (64 bit). Versions 3.2.5, 3.3.6, and 3.4.3 contain a patch for the issue.
- Severity
- high
- Software
- Python
- Fixed in
- 3.4.3
- Published
- 2025-11-10
Affected versions
From: 3.4.0
Until: 3.4.3
Fixed in: 3.4.3
How to fix this CVE
Update Python's OpenEXR library to version 3.4.3 or later to patch a memory safety vulnerability in the legacy Python adapter. This vulnerability affects the InputFile.channel() and InputFile.channels() methods when processing untrusted EXR image files, potentially allowing heap corruption or application crashes. Immediately upgrade affected systems and validate that no legacy OpenEXR Python code is processing user-supplied EXR files without validation.
sudo dnf update python3-openexrDefensia detects this vulnerability
How to check if you are affected
- Check installed OpenEXR version with: pip3 show openexr | grep Version
- Identify Python processes using OpenEXR: grep -r 'import OpenEXR' /path/to/application/code
- Search application logs for EXR file processing errors: grep -i 'exr\|channel\|InputFile' /var/log/application.log
- Verify patch installation by running: python3 -c 'import OpenEXR; print(OpenEXR.__version__)' and confirm version is >= 3.4.3
FAQ
What is CVE-2025-64182?
CVE-2025-64182 is a memory safety vulnerability in OpenEXR's Python adapter that allows integer overflow and unchecked memory allocation when parsing EXR image files, potentially leading to heap corruption or code execution on affected systems.
Is CVE-2025-64182 being actively exploited?
No, this vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and no public exploits are currently available.
What versions of Python/OpenEXR are affected by CVE-2025-64182?
OpenEXR versions 3.2.0–3.2.4, 3.3.0–3.3.5, and 3.4.0–3.4.2 are affected. The vulnerability exists in the legacy Python wrapper and has been patched in versions 3.2.5, 3.3.6, and 3.4.3.
How do I check if my server is vulnerable to CVE-2025-64182?
Run 'pip3 list | grep -i openexr' to identify the installed version. If the version is 3.4.0, 3.4.1, or 3.4.2 (or 3.2.0–3.2.4 or 3.3.0–3.3.5), your system is vulnerable.
Does Defensia detect CVE-2025-64182?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If OpenEXR is installed on a monitored server, CVE-2025-64182 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/AcademySoftwareFoundation/openexr/blob/b3a19903db0672c63055023aa788e592b16ec3c5/src/wrappers/python/PyOpenEXR_old.cpp#L528-L536
- https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-vh63-9mqx-wmjr
- https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-vh63-9mqx-wmjr
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-64182. Free for 1 server.
Get started free