Root has patched CVE-2025-12840 in the rootio-openexr package for Root:Debian:13. Multiple fixed versions available.
{ "distro": "debian", "source": "Root", "distro_version": "13" }
"3.1.13-2"
"https://api.root.io/external/osv/ROOT-OS-DEBIAN-13-CVE-2025-12840.json"
[ "3.1.13-2.root.io.7", "3.1.13-2.root.io.8" ]
true
"root.io.7"
2.0