<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:17:02 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:38498 — Important: openexr security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:38498</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openexr, AlmaLinux:9: openexr-devel, AlmaLinux:9: openexr-libs&lt;/p&gt;
&lt;p&gt;OpenEXR is an open-source high-dynamic-range floating-point image file format for high-quality image processing and storage. This document presents a brief overview of OpenEXR and explains concepts that are specific to this format. This package containes the binaries for OpenEXR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing (CVE-2026-41142)
  * OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files (CVE-2026-42216)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openexr, AlmaLinux:9: openexr-devel, AlmaLinux:9: openexr-libs&lt;/p&gt;
&lt;p&gt;OpenEXR is an open-source high-dynamic-range floating-point image file format for high-quality image processing and storage. This document presents a brief overview of OpenEXR and explains concepts that are specific to this format. This package containes the binaries for OpenEXR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing (CVE-2026-41142)
  * OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files (CVE-2026-42216)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:38498</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-42216</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-42216</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: openexr&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: openexr&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-42216</guid>
    </item>
    <item>
      <title>EUVD-2026-365467</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365467</link>
      <description>EUVD-2026-365467</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365467</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42216</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42216</link>
      <description>&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42216</guid>
    </item>
    <item>
      <title>OESA-2026-2364 — OpenEXR security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2364</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: OpenEXR&lt;/p&gt;
&lt;p&gt;OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light &amp;amp;amp;amp; Magic for use in computer imaging applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-41142)&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-42216)&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: OpenEXR&lt;/p&gt;
&lt;p&gt;OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light &amp;amp;amp;amp; Magic for use in computer imaging applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-41142)&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.(CVE-2026-42216)&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2364</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10772-1 — libIex-3_4-33-3.4.11-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10772-1</link>
      <description>&lt;p&gt;libIex-3_4-33-3.4.11-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libIex-3_4-33-3.4.11-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10772-1</guid>
    </item>
    <item>
      <title>RHSA-2026:39024 — Red Hat Security Advisory: openexr security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:39024</link>
      <description>&lt;p&gt;OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:39024</guid>
    </item>
    <item>
      <title>RLSA-2026:38498 — Important: openexr security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:38498</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: openexr&lt;/p&gt;
&lt;p&gt;OpenEXR is an open-source high-dynamic-range floating-point image file format for high-quality image processing and storage. This document presents a brief overview of OpenEXR and explains concepts that are specific to this format.  This package containes the binaries for OpenEXR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing (CVE-2026-41142)&lt;/p&gt;
&lt;p&gt;* OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files (CVE-2026-42216)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: openexr&lt;/p&gt;
&lt;p&gt;OpenEXR is an open-source high-dynamic-range floating-point image file format for high-quality image processing and storage. This document presents a brief overview of OpenEXR and explains concepts that are specific to this format.  This package containes the binaries for OpenEXR.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing (CVE-2026-41142)&lt;/p&gt;
&lt;p&gt;* OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files (CVE-2026-42216)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:38498</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21796-1 — Security update for openexr</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21796-1</link>
      <description>&lt;p&gt;Security update for openexr&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openexr&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21796-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42216</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42216</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: openexr, Ubuntu:Pro:18.04:LTS: openexr, Ubuntu:Pro:20.04:LTS: openexr, Ubuntu:Pro:22.04:LTS: openexr, Ubuntu:Pro:24.04:LTS: openexr, Ubuntu:25.10: openexr, Ubuntu:Pro:26.04:LTS: openexr&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: openexr, Ubuntu:Pro:18.04:LTS: openexr, Ubuntu:Pro:20.04:LTS: openexr, Ubuntu:Pro:22.04:LTS: openexr, Ubuntu:Pro:24.04:LTS: openexr, Ubuntu:25.10: openexr, Ubuntu:Pro:26.04:LTS: openexr&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42216</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2293 — Red Hat Enterprise Linux (openexr): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2293</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (openexr) ausnutzen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (openexr) ausnutzen, um beliebigen Programmcode auszuführen, um Informationen offenzulegen und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2293</guid>
    </item>
  </channel>
</rss>
