[CLSA-2026:1790973101] openexr: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-02 20:31:54 UTC
Description:
- CVE-2025-12495, CVE-2025-12839, CVE-2025-12840: heap buffer overflows in OpenEXRCore chunk reading (memset on a failed read in exr_read_chunk(), packed/unpacked size mismatch of uncompressed tiles, tiled chunk sizes for scanline parts in internal_exr_compute_chunk_offset_size())
Updated packages:
  • openexr-3.1.1-3.el9_8.4.tuxcare.els2.aarch64.rpm
    sha:72e033c140faa14eeb8e00cf3c60eeb9f9a4ec6d3644ea844a1a332ca8cfb345
  • openexr-3.1.1-3.el9_8.4.tuxcare.els2.i686.rpm
    sha:b850cf5f7ec9c8aa3cbc6c01eeb626b06afcd4a5e3a096cc4168a2671c4595f0
  • openexr-3.1.1-3.el9_8.4.tuxcare.els2.x86_64.rpm
    sha:fa43dd95040e16e48110f9c606bd7b15c840a04aa59478517a54ed29e0a972e0
  • openexr-devel-3.1.1-3.el9_8.4.tuxcare.els2.aarch64.rpm
    sha:89d5fd15cf2f20a2c0173bc89bc603d277bd2f12dbd4454ed8c5c0032fd34fc6
  • openexr-devel-3.1.1-3.el9_8.4.tuxcare.els2.i686.rpm
    sha:630b33b253c4b603ead825a8dc602d0c36f37a29965cf9e0ba5250821b75fdf2
  • openexr-devel-3.1.1-3.el9_8.4.tuxcare.els2.x86_64.rpm
    sha:5ea6e5853b3eac31e3901cc66f8b1c0abac47debd468715c26dd3266faaf86e8
  • openexr-libs-3.1.1-3.el9_8.4.tuxcare.els2.aarch64.rpm
    sha:02c2301d4f04afbf0b1d2b0b396dc780bc8c54a4f7d04bcf703818b91da717d9
  • openexr-libs-3.1.1-3.el9_8.4.tuxcare.els2.i686.rpm
    sha:9f13fa720209877ce8f66424667e86dd59418dc2a9531811b6e57edb04b37d10
  • openexr-libs-3.1.1-3.el9_8.4.tuxcare.els2.x86_64.rpm
    sha:90fa9f4f116e6dcbd0120b1ec626aba6693dca4095d842e69a6cdfc8f2cd5b15
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.