Fedora Account System
Red Hat Associate
Red Hat Customer
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:7678 https://access.redhat.com/errata/RHSA-2026:7678
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:7682 https://access.redhat.com/errata/RHSA-2026:7682
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:8869 https://access.redhat.com/errata/RHSA-2026:8869
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8863 https://access.redhat.com/errata/RHSA-2026:8863
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:8871 https://access.redhat.com/errata/RHSA-2026:8871
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:8870 https://access.redhat.com/errata/RHSA-2026:8870
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8888 https://access.redhat.com/errata/RHSA-2026:8888
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:8872 https://access.redhat.com/errata/RHSA-2026:8872
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:12340 https://access.redhat.com/errata/RHSA-2026:12340
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:12341 https://access.redhat.com/errata/RHSA-2026:12341
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:12339 https://access.redhat.com/errata/RHSA-2026:12339
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:12338 https://access.redhat.com/errata/RHSA-2026:12338