Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:38498

Опубликовано: 14 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: openexr security update

OpenEXR is an open-source high-dynamic-range floating-point image file format for high-quality image processing and storage. This document presents a brief overview of OpenEXR and explains concepts that are specific to this format. This package containes the binaries for OpenEXR.

Security Fix(es):

  • OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing (CVE-2026-41142)

  • OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files (CVE-2026-42216)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
openexrx86_643.el9_8.3openexr-3.1.1-3.el9_8.3.x86_64.rpm
openexr-libsi6863.el9_8.3openexr-libs-3.1.1-3.el9_8.3.i686.rpm
openexr-libsx86_643.el9_8.3openexr-libs-3.1.1-3.el9_8.3.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

rocky
17 дней назад

Important: openexr security update

oracle-oval
16 дней назад

ELSA-2026-38499: openexr security update (IMPORTANT)

oracle-oval
19 дней назад

ELSA-2026-38498: openexr security update (IMPORTANT)

suse-cvrf
3 месяца назад

Security update for openexr

CVSS3: 9.1
ubuntu
3 месяца назад

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.