OpenEXR-2.2.0-12.el8_10.1

エラータID: AXSA:2026-542:02

Release date: 
Monday, May 4, 2026 - 19:25
Subject: 
OpenEXR-2.2.0-12.el8_10.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

OpenEXR is a high dynamic-range (HDR) image file format developed by Industrial Light & Magic for use in computer imaging applications. This package contains libraries and sample applications for handling the format.

Security Fix(es):

* openexr: OpenEXR: Arbitrary code execution via integer overflow in EXR file processing (CVE-2026-27622)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-27622
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. OpenEXR-2.2.0-12.el8_10.1.src.rpm
    MD5: 4d771f13d8cefb2ad54999459f293ec4
    SHA-256: 0c35aa793282b177e92cc302252e90643aca7b0f56e944daee235c71f975404b
    Size: 13.62 MB

Asianux Server 8 for x86_64
  1. OpenEXR-devel-2.2.0-12.el8_10.1.i686.rpm
    MD5: b5abf680add7cd21d3dd7495707eaa1e
    SHA-256: eff55384f56f448d17822d0565e22b688d8e295897045091e931f54c1cfb7a10
    Size: 84.84 kB
  2. OpenEXR-devel-2.2.0-12.el8_10.1.x86_64.rpm
    MD5: 72f5ac4499cdf1869e712db8b90bde8e
    SHA-256: d25e27bd791c8aa834403046a6ee956c7797f04c2cbc53c49b6b572f30fd533a
    Size: 84.84 kB
  3. OpenEXR-libs-2.2.0-12.el8_10.1.i686.rpm
    MD5: 8437dd88a6d551a2fe4d2776c3816dd8
    SHA-256: fa8e5235f036776759da106d09977bfd96460918c4fd3e26784e0d6d3a141a5b
    Size: 701.92 kB
  4. OpenEXR-libs-2.2.0-12.el8_10.1.x86_64.rpm
    MD5: b89e436f85dcc54ce0e7c3a0904384cb
    SHA-256: 80b97b4847bbdfbb56d1718a29e0e3aed280afa5f018e12897b12da0f1d7b04f
    Size: 671.61 kB