{"id":"SUSE-SU-2026:21796-1","summary":"Security update for openexr","details":"This update for openexr fixes the following issues\n\n- CVE-2026-41142: integer overflow in `ImageChannel: resize` can lead to a heap out-of-bounds write via OpenEXRUtil\n  public API (bsc#1264356).\n- CVE-2026-42216: missing checks in `IDManifest: init()` can lead to out-of-bounds read during prefix expansion\n  (bsc#1264354).\n- CVE-2026-42217: missing bounds check for shift counter in `readVariableLengthInteger` can lead to shift exponent\n  overflow and cause undefined behavior (bsc#1264353).\n","modified":"2026-05-28T18:24:01.679609616Z","published":"2026-05-15T08:16:09Z","related":["CVE-2026-41142","CVE-2026-42216","CVE-2026-42217"],"upstream":["CVE-2026-41142","CVE-2026-42216","CVE-2026-42217"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621796-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264353"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264354"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41142"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42217"}],"schema_version":"1.7.5"}