SUSE-SU-2026:21796-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621796-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21796-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:21796-1
Upstream
CVE (3)
Related
Published
2026-05-15T08:16:09Z
Modified
2026-05-28T18:24:09Z
Summary
Security update for openexr
Details

This update for openexr fixes the following issues

  • CVE-2026-41142: integer overflow in ImageChannel: resize can lead to a heap out-of-bounds write via OpenEXRUtil public API (bsc#1264356).
  • CVE-2026-42216: missing checks in IDManifest: init() can lead to out-of-bounds read during prefix expansion (bsc#1264354).
  • CVE-2026-42217: missing bounds check for shift counter in readVariableLengthInteger can lead to shift exponent overflow and cause undefined behavior (bsc#1264353).
References

Affected packages