{"id":"CVE-2025-48073","aliases":["GHSA-qhpm-86v7-phmm","PYSEC-2026-1748"],"url":"https://o3.security/vulnerability/CVE-2025-48073","summary":"OpenEXR ScanLineProcess::run_fill NULL Pointer Write In \"reduceMemory\" Mode","details":"OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target application with a NULL pointer dereference in a write operation. This is fixed in version 3.3.3.","published":"2025-07-31T20:25:51.545Z","modified":"2026-07-15T01:48:59.951675615Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"openexr","fixedVersion":"3.3.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ShielderSec/poc/tree/main/CVE-2025-48073"},{"type":"ADVISORY","url":"https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-qhpm-86v7-phmm"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48073.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48073"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:59.951675615Z"}}