Описание
Security update for openexr
This update for openexr fixes the following issue
- CVE-2026-41142: integer overflow in
ImageChannel: resizecan lead to a heap out-of-bounds write via OpenEXRUtil public API (bsc#1264356).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise Server 15 SP4-LTSS
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise Server 15 SP5-LTSS
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise Server 15 SP6-LTSS
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
libIlmImf-2_2-23-2.2.1-150000.3.49.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
openexr-devel-2.2.1-150000.3.49.1
Ссылки
- Link for SUSE-SU-2026:2114-1
- E-Mail link for SUSE-SU-2026:2114-1
- SUSE Security Ratings
- SUSE Bug 1264356
- SUSE CVE CVE-2026-41142 page
Описание
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libIlmImf-2_2-23-2.2.1-150000.3.49.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:openexr-devel-2.2.1-150000.3.49.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libIlmImf-2_2-23-2.2.1-150000.3.49.1
Ссылки
- CVE-2026-41142
- SUSE Bug 1264356