{"id":"openSUSE-SU-2026:20755-1","summary":"Security update for openexr","details":"This update for openexr fixes the following issues\n\n- CVE-2026-41142: integer overflow in `ImageChannel: resize` can lead to a heap out-of-bounds write via OpenEXRUtil\n  public API (bsc#1264356).\n- CVE-2026-42216: missing checks in `IDManifest: init()` can lead to out-of-bounds read during prefix expansion\n  (bsc#1264354).\n- CVE-2026-42217: missing bounds check for shift counter in `readVariableLengthInteger` can lead to shift exponent\n  overflow and cause undefined behavior (bsc#1264353).\n","modified":"2026-05-19T18:23:50.519518287Z","published":"2026-05-15T08:14:43Z","related":["CVE-2026-41142","CVE-2026-42216","CVE-2026-42217"],"upstream":["CVE-2026-41142","CVE-2026-42216","CVE-2026-42217"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264353"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264354"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41142"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42217"}],"schema_version":"1.7.5"}