This update for openexr fixes the following issue:
CVE-2026-88384: NULL pointer dereference in the C++ attribute parsing path when a specially crafted EXR file
containing an unknown-type attribute with dataSize set to zero is processed (bsc#1282700).