CVE-2025-64183 | AcademySoftwareFoundation OpenEXR up to 3.2.4/3.3.5/3.4.2 EXR File Parser pyOpenEXR_old.cpp PyObject_StealAttrString use after free (GHSA-57cw-j6vp-2p9m)
A vulnerability classified as critical has been found in AcademySoftwareFoundation OpenEXR up to 3.2.4/3.3.5/3.4.2. The affected element is the function PyObject_StealAttrString of the file pyOpenEXR_old.cpp of the component EXR File Parser. The manipulation leads to use after free.
This vulnerability is traded as CVE-2025-64183. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.