[CLSA-2026:1790590713] openexr: Fix of CVE-2026-42217
Type:
security
Severity:
Critical
Release date:
2026-09-28 15:10:15 UTC
Description:
- CVE-2026-42217: reject IDManifest variable-length integers whose shift reaches 64 bits, avoiding undefined behaviour in readVariableLengthInteger()
CVEs fixed:
Updated packages:
  • openexr-3.1.1-3.el9_8.4.tuxcare.els1.aarch64.rpm
    sha:82c5a7ba91e88b5c48cac84d4297e746851184cdae66d193226cce01a52b2c51
  • openexr-3.1.1-3.el9_8.4.tuxcare.els1.i686.rpm
    sha:257197f8b2099e6358bd2880744c779e75f0fe92ffc6b9ae6319ef0f4d842fb2
  • openexr-3.1.1-3.el9_8.4.tuxcare.els1.x86_64.rpm
    sha:f1ecad16c166140ee1b0db6e7b2870ee0187a93a966c7df3f51defa69aacaeeb
  • openexr-devel-3.1.1-3.el9_8.4.tuxcare.els1.aarch64.rpm
    sha:db682b9ca9ec9a48682465d474792b4d3d65b2246b3438a3c1b193d75fa1f5c6
  • openexr-devel-3.1.1-3.el9_8.4.tuxcare.els1.i686.rpm
    sha:729d64d6debd121940104447bfd95f7913f2f8fbc68ee53f94461eb370d467b0
  • openexr-devel-3.1.1-3.el9_8.4.tuxcare.els1.x86_64.rpm
    sha:c8c3b5bf53b1e3dea779e17c1358944e1ac7520c4e0c91ee1b8226efe70d727a
  • openexr-libs-3.1.1-3.el9_8.4.tuxcare.els1.aarch64.rpm
    sha:3de3dd6805e0661a49929cde035f68d0d672a565d3ea52720df6aa1ca290be60
  • openexr-libs-3.1.1-3.el9_8.4.tuxcare.els1.i686.rpm
    sha:88fcccdbf7dc95532bd73eb1e7b885642469168e3e90d67211347e78747f2c6d
  • openexr-libs-3.1.1-3.el9_8.4.tuxcare.els1.x86_64.rpm
    sha:b281a766bb2da762fabf682623c8b76c741f2bbdb32e4799a0c96681c401e547
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.