openexr-3.1.1-3.el9_8.4
エラータID: AXSA:2026-1902:06
OpenEXR is an open-source high-dynamic-range floating-point image file format for high-quality image processing and storage. This document presents a brief overview of OpenEXR and explains concepts that are specific to this format. This package containes the binaries for OpenEXR.
Security Fix(es):
* OpenEXR: OpenEXR: Heap out-of-bounds write in exrmultiview via crafted EXR files (CVE-2026-68515)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-68515
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr out.exr with crafted but valid inputs, so this is not solely an API or caller-precondition issue. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Update packages.
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr out.exr with crafted but valid inputs, so this is not solely an API or caller-precondition issue. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
N/A
SRPMS
- openexr-3.1.1-3.el9_8.4.src.rpm
MD5: 86a84c2f47da5eaad07f7e6638172e42
SHA-256: c0b0974b47c293ce66a9bcb3d2773dad9242b67ff2a4bbc35ddc4edd6470e499
Size: 24.20 MB
Asianux Server 9 for x86_64
- openexr-3.1.1-3.el9_8.4.x86_64.rpm
MD5: 5d6448cf41d7a1bbfd899e835405d568
SHA-256: 918c453084be4e1374df04386caff878037429ec7b88612b52dcc0ca7dc10a32
Size: 115.71 kB - openexr-devel-3.1.1-3.el9_8.4.i686.rpm
MD5: 7f74553e87a9a3b9d07c962be5f77f26
SHA-256: dbd15d3a4b4f3a2634c3c4a5fff5bccf167a81e80bebf1db425f8d97c46af5df
Size: 169.26 kB - openexr-devel-3.1.1-3.el9_8.4.x86_64.rpm
MD5: 80dbe8604461721a630c6f9cc4ed2fa0
SHA-256: dd5d42c526d970d73fab486edebd60e8fd0bb45588d2ec60609395b40f84970c
Size: 169.29 kB - openexr-libs-3.1.1-3.el9_8.4.i686.rpm
MD5: c48bcdeba0d81ae9c3e1c68915a2b7a7
SHA-256: 7ef6cf2615b392be921813be2b0bfbe2c61104260e00ff2537e80696ae8f454d
Size: 1.13 MB - openexr-libs-3.1.1-3.el9_8.4.x86_64.rpm
MD5: 73c49a4c1174e10e883713bacc5a59a6
SHA-256: 8ec089cfca266d3385d13197bd4c15fb68a9e47b17e3b576973e7ac18e4c8f4d
Size: 1.07 MB