openexr-3.1.1-3.el9_7.1

エラータID: AXSA:2026-479:01

Release date: 
Tuesday, April 21, 2026 - 15:44
Subject: 
openexr-3.1.1-3.el9_7.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

OpenEXR is an open-source high-dynamic-range floating-point image file format for high-quality image processing and storage. This document presents a brief overview of OpenEXR and explains concepts that are specific to this format. This package containes the binaries for OpenEXR.

Security Fix(es):

* openexr: OpenEXR: Arbitrary code execution via integer overflow in EXR file processing (CVE-2026-27622)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-27622
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. openexr-3.1.1-3.el9_7.1.src.rpm
    MD5: 9c296037c76b74592691465d10843a90
    SHA-256: 4945364d83f46fea76156a9e9bcce7b79df2da1d5a25d034d9ebea607dfe00e8
    Size: 24.20 MB

Asianux Server 9 for x86_64
  1. openexr-3.1.1-3.el9_7.1.x86_64.rpm
    MD5: 99e7a061d9bb65b16cde0ecf649a0c28
    SHA-256: 9ccde2c3b89c28b1e2e61291c18494325ddda9bfa7c1c7869512ad5c59550229
    Size: 115.01 kB
  2. openexr-devel-3.1.1-3.el9_7.1.i686.rpm
    MD5: f4dbd0999ab08ebb51e077a3bcca20dd
    SHA-256: f014a416cee23463f5accb1a19e5172a7f19c8945ff6a743abb34f2f082f381d
    Size: 168.96 kB
  3. openexr-devel-3.1.1-3.el9_7.1.x86_64.rpm
    MD5: cf68ed272587d73d844921eaa5012f02
    SHA-256: 4a2be77c50e7e9133b19883eb10de221c6e9722999d1832af374fa5561d6e72c
    Size: 169.07 kB
  4. openexr-libs-3.1.1-3.el9_7.1.i686.rpm
    MD5: 6934923fba28e827b679cb0ffa9aa3b2
    SHA-256: 155f6bf6668e554e2ed4488a31df3482c710d8779d5201cde415d2e1e1a7383d
    Size: 1.12 MB
  5. openexr-libs-3.1.1-3.el9_7.1.x86_64.rpm
    MD5: ba0c187d2b83174f21b39c1ae44b0db0
    SHA-256: 3792cfc239d9d4d2bb68cbce703da75987633673e016fbe946f3d8280213ad44
    Size: 1.07 MB