openexr-3.1.1-3.el9_8.3
エラータID: AXSA:2026-1493:05
リリース日:
2026/08/07 Friday - 21:18
題名:
openexr-3.1.1-3.el9_8.3
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- OpenEXR の ImageChannel::resize() 関数には、整数オーバーフロー
の問題があるため、リモートの攻撃者により、巧妙に細工された OpenEXR
画像ファイルを介して、任意のコードの実行、情報の漏洩、および
サービス拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-41142)
- OpenEXR の IDManifest::init() 関数には、メモリ領域の範囲外
読み取りの問題があるため、リモートの攻撃者により、巧妙に細工された
EXR ファイルを介して、情報の漏洩、およびサービス拒否攻撃 (DoS) を
可能とする脆弱性が存在します。(CVE-2026-42216)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-41142
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
CVE-2026-42216
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
追加情報:
N/A
ダウンロード:
SRPMS
- openexr-3.1.1-3.el9_8.3.src.rpm
MD5: 84ed703363d8d5134df878ebe547edec
SHA-256: 1963c753df2c6b01224d6fbffb8503c68b0780dabf38a20b6fae9fd10ba97535
Size: 24.20 MB
Asianux Server 9 for x86_64
- openexr-3.1.1-3.el9_8.3.x86_64.rpm
MD5: c2b874b698d9f95cfdd57606c3b44864
SHA-256: 7d372374dfb5b50f3a70bf3c2791020844887ed36e193536891f2fcdcbb3cf3e
Size: 115.19 kB - openexr-devel-3.1.1-3.el9_8.3.i686.rpm
MD5: f14fc650e1afef66479566aae20508c3
SHA-256: 587723fdd19626a6285b84b818267173ce8bfa4632c31ca1140c840acb58bdd4
Size: 169.23 kB - openexr-devel-3.1.1-3.el9_8.3.x86_64.rpm
MD5: ea8222db564fecafc72e67e2cd56663f
SHA-256: 6b036c88015eba34fa7e5c2734ee6f26a84107c14f0d3765c239c59156424ac5
Size: 169.21 kB - openexr-libs-3.1.1-3.el9_8.3.i686.rpm
MD5: 31619c3cdc31fca18e6e8944e316bb44
SHA-256: 983a2be6d6f1e03a566a70da9312183db948c05261a28a94c42fea840dad44ab
Size: 1.13 MB - openexr-libs-3.1.1-3.el9_8.3.x86_64.rpm
MD5: 3112226fa12bedd5a1c85fee249997ef
SHA-256: 6ebdce0ecc111f598e2e8fa8886e12fcf50e8df3f4ae320c962274d97797f0a8
Size: 1.07 MB