Bug 2315819 - openexr-3.4.12 is available
Summary: openexr-3.4.12 is available
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: openexr
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Richard Shaw
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 2455190
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-10-01 03:17 UTC by Upstream Release Monitoring
Modified: 2026-05-25 21:23 UTC (History)
3 users (show)

Fixed In Version: openexr-3.4.12-1.fc45
Clone Of:
Environment:
Last Closed: 2026-05-25 21:23:27 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Upstream Release Monitoring 2024-10-01 03:17:13 UTC
Releases retrieved: 3.3.0
Upstream release that is considered latest: 3.3.0
Current version/release in rawhide: 3.2.4-3.fc41
URL: https://www.openexr.com/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 1 Upstream Release Monitoring 2024-10-10 05:22:27 UTC
Releases retrieved: 3.3.1
Upstream release that is considered latest: 3.3.1
Current version/release in rawhide: 3.2.4-3.fc41
URL: https://www.openexr.com/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 2 Upstream Release Monitoring 2024-11-12 14:05:39 UTC
Releases retrieved: 3.3.2
Upstream release that is considered latest: 3.3.2
Current version/release in rawhide: 3.2.4-3.fc41
URL: https://www.openexr.com/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 3 Upstream Release Monitoring 2025-03-24 04:52:43 UTC
Releases retrieved: 3.3.3
Upstream release that is considered latest: 3.3.3
Current version/release in rawhide: 3.2.4-3.fc41
URL: https://www.openexr.com/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 4 Upstream Release Monitoring 2025-06-09 02:21:09 UTC
Releases retrieved: 3.3.4
Upstream release that is considered latest: 3.3.4
Current version/release in rawhide: 3.2.4-3.fc41
URL: https://www.openexr.com/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 5 Xose Vazquez Perez 2025-07-09 09:20:03 UTC
(In reply to Upstream Release Monitoring from comment #4)

> Releases retrieved: 3.3.4
> Upstream release that is considered latest: 3.3.4
> Current version/release in rawhide: 3.2.4-3.fc41
> URL: https://www.openexr.com/
> Based on the information from Anitya: https://release-monitoring.org/project/13289/
> To change the monitoring settings for the project, please visit: https://src.fedoraproject.org/rpms/openexr

A lot of changes in 3.3.4 (June 9, 2025) since 3.2.4 (March 26, 2024):
https://github.com/AcademySoftwareFoundation/openexr/blob/main/CHANGES.md

Comment 6 Richard Shaw 2025-07-10 12:15:15 UTC
I was able to build 3.3.4 after making a few adjustments to the spec file, the more difficult part is that this includes a soname change so the build, and rebuild of all the dependencies will need to be coordinated.

Here's the dependencies:
CImg
CTL
ImageMagick
OpenColorIO
OpenEXR_Viewers
OpenImageIO
OpenSceneGraph
YafaRay
blender
darktable
enblend
freeimage
gdal
geeqie
gegl04
gimp
gmic
gstreamer1-plugins-bad-free
hugin
jpegxl
kdelibs3
kf5-kimageformats
kf6-kimageformats
kio-extras
kio-extras-kf5
krita
luminance-hdr
luxcorerender
ogre
olive
opencv
openvdb
pfstools
povray
prusa-slicer
swayimg
synfig
vigra
vips

Comment 7 Upstream Release Monitoring 2025-07-26 23:30:11 UTC
Releases retrieved: 3.3.5
Upstream release that is considered latest: 3.3.5
Current version/release in rawhide: 3.2.4-3.fc41
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 8 Upstream Release Monitoring 2025-08-03 00:14:54 UTC
Releases retrieved: 3.4-alpha
Upstream release that is considered latest: 3.4-alpha
Current version/release in rawhide: 3.2.4-6.fc43
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 9 Upstream Release Monitoring 2025-09-05 20:09:40 UTC
Releases retrieved: 3.4.0
Upstream release that is considered latest: 3.4.0
Current version/release in rawhide: 3.2.4-6.fc43
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 10 Upstream Release Monitoring 2025-10-08 23:09:55 UTC
Releases retrieved: 3.4.1
Upstream release that is considered latest: 3.4.1
Current version/release in rawhide: 3.2.4-6.fc43
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 11 Upstream Release Monitoring 2025-10-16 15:57:48 UTC
Releases retrieved: 3.4.2
Upstream release that is considered latest: 3.4.2
Current version/release in rawhide: 3.2.4-6.fc43
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 12 Upstream Release Monitoring 2025-11-05 02:58:24 UTC
Releases retrieved: 3.2.5, 3.3.6, 3.4.3
Upstream release that is considered latest: 3.4.3
Current version/release in rawhide: 3.2.4-6.fc43
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 13 Upstream Release Monitoring 2025-11-19 22:52:19 UTC
Releases retrieved: 3.4.4
Upstream release that is considered latest: 3.4.4
Current version/release in rawhide: 3.2.4-6.fc43
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 14 David Auer 2025-11-23 20:04:05 UTC
I feel like we are not achieving our "first" goal here, is there anything I can do to help?

Would it make sense to get the latest version in rawhide right now so that we have at least something recent when f44 is branched? (I think I could try to build it all in a side-tag but I've never used that in practice before.)
Or should we wait for something to make it worthwile?

Furthermore I see some CVEs listed in the Github, should we consider issuing 3.2.5 as an update for f43 and f42? It would at least close two CVEs but I can't say if or how vulnerable they really are.

According to the support table I'd say we should aim at least for 3.4 for f44, better 3.5 if possible: https://github.com/AcademySoftwareFoundation/openexr/security#supported-versions

Comment 15 Miloš Komarčević 2025-11-27 10:16:01 UTC
> Would it make sense to get the latest version in rawhide right now so that we have at least something recent when f44 is branched?

3.4.x should indeed ideally make it for f44 (together w/ imath 3.2.x and OpenColorIO 2.5.x) in order to intersect next year's VFX reference platform [1][2]. 

[1] https://vfxplatform.com/
[2] https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/FWWFHJNLZJCNEK7XREBWQ36NNKVEFF23/

Comment 16 David Auer 2025-12-13 15:27:47 UTC
Correction of my previous comment, I meant at least 3.3 for f44, better 3.4 if possible. (There is no 3.5 therefore we shouldn't try to ship it ;))
With Milo's comment that's definitely rather 3.4.


@Richard: Is there anything I can do to help? I feel like f44 is already approaching with change proposal deadlines in 10 days and mass rebuild in less than a month. - I guess those are not necessary for updating openexr but I feel like now would be a good time to get the ball rolling.(In reply to

Comment 17 Richard Shaw 2025-12-14 02:43:38 UTC
There are a lot of build deps for openexr so a compat package is likely required. I haven't had time to build/support that:
https://copr.fedorainfracloud.org/coprs/hobbes1069/openexr/builds/

Comment 18 Upstream Release Monitoring 2026-02-21 22:47:50 UTC
Releases retrieved: 3.4.5
Upstream release that is considered latest: 3.4.5
Current version/release in rawhide: 3.2.4-7.fc44
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 19 Upstream Release Monitoring 2026-03-01 21:33:20 UTC
Releases retrieved: 3.2.6, 3.3.8, 3.4.6
Upstream release that is considered latest: 3.4.6
Current version/release in rawhide: 3.2.4-7.fc44
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 20 Upstream Release Monitoring 2026-03-15 21:49:14 UTC
Releases retrieved: 3.4.7
Upstream release that is considered latest: 3.4.7
Current version/release in rawhide: 3.2.4-7.fc44
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 21 Upstream Release Monitoring 2026-03-26 16:39:04 UTC
Releases retrieved: 3.4.8
Upstream release that is considered latest: 3.4.8
Current version/release in rawhide: 3.2.4-7.fc44
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 22 Upstream Release Monitoring 2026-04-03 21:15:32 UTC
Releases retrieved: 3.2.7, 3.3.9, 3.4.9
Upstream release that is considered latest: 3.4.9
Current version/release in rawhide: 3.2.4-7.fc44
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 23 Upstream Release Monitoring 2026-04-17 17:14:44 UTC
Releases retrieved: 3.2.8, 3.3.10, 3.4.10
Upstream release that is considered latest: 3.4.10
Current version/release in rawhide: 3.2.4-7.fc44
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 24 Xose Vazquez Perez 2026-04-19 10:45:48 UTC
Meanwhile, it could be updated to the latest version (3.2.8) from the 3.2 branch:

https://github.com/AcademySoftwareFoundation/openexr/blob/RB-3.2/CHANGES.md


## Version 3.2.8 (April 17, 2026)

Patch release that addresses the following security vulnerabilities:

* [CVE-2026-40244](https://www.cve.org/CVERecord?id=CVE-2026-40244) Integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed variant of CVE-2026-34589)
* [CVE-2026-40250](https://www.cve.org/CVERecord?id=CVE-2026-40250) Integer overflow in DWA decoder outBufferEnd pointer arithmetic (missed variant of CVE-2026-34589)

### Merged Pull Requests

* [2346](https://github.com/AcademySoftwareFoundation/openexr/pull/2346)
Fix integer overflow in internal_dwa_compressor.h

## Version 3.2.7 (April 3, 2026)

Patch release for v3.2 that addresses the following security vulnerabilities:

* [CVE-2026-34589](https://www.cve.org/CVERecord?id=CVE-2026-34589) DWA Lossy Decoder Heap Out-of-Bounds Write
* [CVE-2026-34588](https://www.cve.org/CVERecord?id=CVE-2026-34588) Signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
* [CVE-2026-34544](https://www.cve.org/CVERecord?id=CVE-2026-34544) integer overflow to OOB write in uncompress_b44_impl()
* [CVE-2026-34543](https://www.cve.org/CVERecord?id=CVE-2026-34543) Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)
* [CVE-2026-34380](https://www.cve.org/CVERecord?id=CVE-2026-34380) Signed integer overflow (undefined behavior) in undo_pxr24_impl may allow bounds-check bypass in PXR24 decompression
* [CVE-2026-34379](https://www.cve.org/CVERecord?id=CVE-2026-34379) Misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression)

### Merged Pull Requests

* [2329](https://github.com/AcademySoftwareFoundation/openexr/pull/2329)
Fix signed integer overflow in `LossyDctDecoder_execute()` pointer arithmatic
* [2328](https://github.com/AcademySoftwareFoundation/openexr/pull/2328)
fix integer overflow in PIZ wavelet buffer arithmetic
* [2324](https://github.com/AcademySoftwareFoundation/openexr/pull/2324)
Fix misaligned memory access in `LossyDctDecoder_execute` HALF→FLOAT expansion
* [2323](https://github.com/AcademySoftwareFoundation/openexr/pull/2323)
fix signed integer overflow in `undo_pxr24_impl()`
* [2312](https://github.com/AcademySoftwareFoundation/openexr/pull/2312)
Fix B44/B44A integer overflow: use uint64_t for row offset
* [2310](https://github.com/AcademySoftwareFoundation/openexr/pull/2310)
PXR24: reject zlib output that does not match packed payload size

### Merged Workflow Pull Requests


## Version 3.2.6 (February 26, 2026)

Patch release that prevents an integer overflow when using the
CompositeDeepScanLine API to combine multiple deep parts.

### Merged Pull Requests:

* [2256](https://github.com/AcademySoftwareFoundation/pulls/2256)


## Version 3.2.5 (November 4, 2025)

Patch release that addresses bugs in the python module's legacy API.

- Buffer overflow in PyOpenEXR_old's `channels()` and `channel()` in
  legacy python, reported by Joshua Rogers (GitHub: MegaManSec).
- Use after free in PyObject_StealAttrString in legacy python, reported
  by Joshua Rogers (GitHub: MegaManSec).

### Merged Pull Requests:

* [2168](https://github.com/AcademySoftwareFoundation/openexr/pull/2168)
 Fix improper use of `Py_DECREF` in legacy python module
* [2163](https://github.com/AcademySoftwareFoundation/openexr/pull/2163)
Check for image size overflow in legacy python module

Comment 25 Upstream Release Monitoring 2026-04-30 00:34:17 UTC
Releases retrieved: 3.2.9, 3.3.11, 3.4.11
Upstream release that is considered latest: 3.4.11
Current version/release in rawhide: 3.2.4-7.fc44
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 26 Xose Vazquez Perez 2026-04-30 07:22:16 UTC
(In reply to Upstream Release Monitoring from comment #25)

> Releases retrieved: 3.2.9, 3.3.11, 3.4.11
> Upstream release that is considered latest: 3.4.11
> Current version/release in rawhide: 3.2.4-7.fc44
> URL: https://www.openexr.com
> Based on the information from Anitya: https://release-monitoring.org/project/13289/
> To change the monitoring settings for the project, please visit: https://src.fedoraproject.org/rpms/openexr

## Version 3.2.9 (April 29, 2026)

Patch release for 3.2 that addresses the following security
vulnerabilities:

* [CVE-2026-42217](https://www.cve.org/CVERecord?id=CVE-2026-42217)
Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`)
* [CVE-2026-42216](https://www.cve.org/CVERecord?id=CVE-2026-42216)
Out-of-bounds read in `IDManifest::init()` during prefix expansion
* [CVE-2026-41142](https://www.cve.org/CVERecord?id=CVE-2026-41142)
Integer overflow in `ImageChannel::resize` leads to heap OOB write via OpenEXRUtil public API

Also:

* OSS-fuzz [504280155](https://issues.oss-fuzz.com/issues/504280155)
Heap-buffer-overflow in `DwaCompressor_uncompress`

### Merged Pull Requests

* [2383](https://github.com/AcademySoftwareFoundation/openexr/pull/2383)
validate that the uncompressed sizes recorded in the dwa header are valid
* [2378](https://github.com/AcademySoftwareFoundation/openexr/pull/2378)
Harden IDManifest parsing against illegal shift and string prefix OOB
* [2377](https://github.com/AcademySoftwareFoundation/openexr/pull/2377)
Fix OOB read when expanding IDManifest prefix-compressed strings
* [2367](https://github.com/AcademySoftwareFoundation/openexr/pull/2367)
Fix int overflow in ImageChannel::resize pixel count

Comment 27 Upstream Release Monitoring 2026-05-24 20:07:42 UTC
Releases retrieved: 3.4.12
Upstream release that is considered latest: 3.4.12
Current version/release in rawhide: 3.2.4-7.fc44
URL: https://www.openexr.com

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/13289/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/openexr

Comment 28 Fedora Update System 2026-05-25 20:07:30 UTC
FEDORA-2026-311ff60aba (blender-5.1.1-4.fc45, CImg-3.7.6-3.fc45, and 35 more) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-311ff60aba

Comment 29 Fedora Update System 2026-05-25 21:23:27 UTC
FEDORA-2026-311ff60aba (blender-5.1.1-4.fc45, CImg-3.7.6-3.fc45, and 35 more) has been pushed to the Fedora 45 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.