openSUSE-SU-2026:20755-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20755-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20755-1
Upstream
CVE (3)
Related
Published
2026-05-15T08:14:43Z
Modified
2026-05-19T18:23:50Z
Summary
Security update for openexr
Details

This update for openexr fixes the following issues

  • CVE-2026-41142: integer overflow in ImageChannel: resize can lead to a heap out-of-bounds write via OpenEXRUtil public API (bsc#1264356).
  • CVE-2026-42216: missing checks in IDManifest: init() can lead to out-of-bounds read during prefix expansion (bsc#1264354).
  • CVE-2026-42217: missing bounds check for shift counter in readVariableLengthInteger can lead to shift exponent overflow and cause undefined behavior (bsc#1264353).
References

Affected packages