Fedora Account System
Red Hat Associate
Red Hat Customer
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:38499 https://access.redhat.com/errata/RHSA-2026:38499
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:38498 https://access.redhat.com/errata/RHSA-2026:38498
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:39024 https://access.redhat.com/errata/RHSA-2026:39024
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:39027 https://access.redhat.com/errata/RHSA-2026:39027
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:39026 https://access.redhat.com/errata/RHSA-2026:39026
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:39025 https://access.redhat.com/errata/RHSA-2026:39025