{"id":"SUSE-SU-2026:23604-1","summary":"Security update for openexr","details":"This update for openexr fixes the following issues:\n\n- CVE-2026-59183: unmapped memory access leading to crash due to `int32_t` multiplication overflow in\n  `unpack_sample_table()` when decoding a crafted deep tiled EXR file (bsc#1276428).\n- CVE-2026-59184: out-of-bounds or use-after-free writes when processing a crafted EXR with a nonzero `dataWindow.min`\n  (bsc#1276849).\n- CVE-2026-59186: heap out-of-bounds write on 32-bit/ILP32 builds when a crafted tiled EXR is read through the public\n  `TiledRgbaInputFile` RGBA API (bsc#1276850).\n- CVE-2026-59189: heap out-of-bounds read when processing a deep image that has a non-zero `dataWindow` origin\n  (bsc#1276855).\n- CVE-2026-59981: heap out-of-bounds read when procesing a deep image that has a non-zero `dataWindow` origin\n  (bsc#1276862).\n- CVE-2026-59982: out-of-bounds pointer access when processing a crafted deep EXR that has a non-zero `dataWindow`\n  origin (bsc#1276853).\n- CVE-2026-59983: out-of-bounds read in ILP32 builds when processing a crafted uncompressed deep-tile EXR\n  (bsc#1276856).\n- CVE-2026-59984: out-of-bounds write in ILP32 builds when processing a crafted B44-compressed scanline EXR\n  (bsc#1276857).\n- CVE-2026-59985: out-of-bounds read in ILP32 builds when processing a crafted RLE-compressed EXR\n  (bsc#1276858).\n- CVE-2026-61555: undefined behavior when processing a crafted EXR with an empty `multiView` header attribute\n  (bsc#1276859).\n- CVE-2026-68515: heap out-of-bounds write in `exrmultiview` when combining two specially crafted, individually valid\n  scanline EXR files whose union `dataWindow` is not aligned to one view's channel subsampling (bsc#1276848).\n","modified":"2026-09-29T18:23:19.102204578Z","published":"2026-09-02T09:40:54Z","related":["CVE-2026-59183","CVE-2026-59184","CVE-2026-59186","CVE-2026-59189","CVE-2026-59981","CVE-2026-59982","CVE-2026-59983","CVE-2026-59984","CVE-2026-59985","CVE-2026-61555","CVE-2026-68515"],"upstream":["CVE-2026-59183","CVE-2026-59184","CVE-2026-59186","CVE-2026-59189","CVE-2026-59981","CVE-2026-59982","CVE-2026-59983","CVE-2026-59984","CVE-2026-59985","CVE-2026-61555","CVE-2026-68515"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623604-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276848"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276849"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276850"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276853"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276856"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276857"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276858"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276859"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59183"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59184"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59189"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61555"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-68515"}],"affected":[{"package":{"name":"openexr","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/openexr&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.2-160000.10.1"}]}],"ecosystem_specific":{"binaries":[{"libOpenEXRUtil-3_2-31-x86-64-v3":"3.2.2-160000.10.1","libOpenEXR-3_2-31-x86-64-v3":"3.2.2-160000.10.1","libOpenEXRCore-3_2-31-x86-64-v3":"3.2.2-160000.10.1","openexr":"3.2.2-160000.10.1","libIex-3_2-31":"3.2.2-160000.10.1","libOpenEXR-3_2-31":"3.2.2-160000.10.1","openexr-doc":"3.2.2-160000.10.1","libOpenEXRCore-3_2-31":"3.2.2-160000.10.1","libIlmThread-3_2-31":"3.2.2-160000.10.1","libIlmThread-3_2-31-x86-64-v3":"3.2.2-160000.10.1","libOpenEXRUtil-3_2-31":"3.2.2-160000.10.1","libIex-3_2-31-x86-64-v3":"3.2.2-160000.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23604-1.json"}},{"package":{"name":"openexr","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/openexr&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.2-160000.10.1"}]}],"ecosystem_specific":{"binaries":[{"libIlmThread-3_2-31-x86-64-v3":"3.2.2-160000.10.1","openexr":"3.2.2-160000.10.1","libOpenEXRUtil-3_2-31-x86-64-v3":"3.2.2-160000.10.1","libOpenEXRCore-3_2-31-x86-64-v3":"3.2.2-160000.10.1","libOpenEXRUtil-3_2-31":"3.2.2-160000.10.1","libIlmThread-3_2-31":"3.2.2-160000.10.1","libOpenEXR-3_2-31-x86-64-v3":"3.2.2-160000.10.1","libIex-3_2-31":"3.2.2-160000.10.1","libOpenEXR-3_2-31":"3.2.2-160000.10.1","libIex-3_2-31-x86-64-v3":"3.2.2-160000.10.1","libOpenEXRCore-3_2-31":"3.2.2-160000.10.1","openexr-doc":"3.2.2-160000.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23604-1.json"}}],"schema_version":"1.9.0"}