A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file that is processed by OpenEXR, to trigger an integer overflow. The highest threat from this vulnerability is to system availability.
https://lists.debian.org/debian-lts-announce/2022/12/msg00022.html
https://github.com/AcademySoftwareFoundation/openexr/pull/836