Описание
Security update for openexr
This update for openexr fixes the following issues
- CVE-2026-54920: unchecked integer overflows in Image::resize() followed by an exception can lead to an invalid delete via uninitialized pointers (bsc#1269703).
- CVE-2026-55059: row setter utilizing dataWindow.min.x instead of min.y can lead to a heap out-of-bounds write (bsc#1269702).
- CVE-2026-55373: integer overflow in roundListSizeUp() wrapping a 32-bit unsigned value to zero can lead to an infinite loop (bsc#1269701).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
libIlmImf-2_2-23-2.2.1-150000.3.52.1
libIlmImfUtil-2_2-23-2.2.1-150000.3.52.1
openexr-devel-2.2.1-150000.3.52.1
Ссылки
- Link for SUSE-SU-2026:3169-1
- E-Mail link for SUSE-SU-2026:3169-1
- SUSE Security Ratings
- SUSE Bug 1269701
- SUSE Bug 1269702
- SUSE Bug 1269703
- SUSE CVE CVE-2026-54920 page
- SUSE CVE CVE-2026-55059 page
- SUSE CVE CVE-2026-55373 page
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libIlmImf-2_2-23-2.2.1-150000.3.52.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libIlmImfUtil-2_2-23-2.2.1-150000.3.52.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:openexr-devel-2.2.1-150000.3.52.1
Ссылки
- CVE-2026-54920
- SUSE Bug 1269703
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libIlmImf-2_2-23-2.2.1-150000.3.52.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libIlmImfUtil-2_2-23-2.2.1-150000.3.52.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:openexr-devel-2.2.1-150000.3.52.1
Ссылки
- CVE-2026-55059
- SUSE Bug 1269702
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libIlmImf-2_2-23-2.2.1-150000.3.52.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libIlmImfUtil-2_2-23-2.2.1-150000.3.52.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:openexr-devel-2.2.1-150000.3.52.1
Ссылки
- CVE-2026-55373
- SUSE Bug 1269701