Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package openexr for openSUSE:Factory checked in at 2026-09-30 16:22:14 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/openexr (Old) and /work/SRC/openSUSE:Factory/.openexr.new.1465845 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "openexr" Wed Sep 30 16:22:14 2026 rev:83 rq:1381394 version:3.4.15 Changes: -------- --- /work/SRC/openSUSE:Factory/openexr/openexr.changes 2026-08-26 19:52:16.472671402 +0200 +++ /work/SRC/openSUSE:Factory/.openexr.new.1465845/openexr.changes 2026-09-30 16:23:07.485532574 +0200 @@ -1,0 +2,9 @@ +Tue Sep 29 09:55:46 UTC 2026 - Petr Gajdos <[email protected]> + +- version update to 3.4.15 + * fixes two memory issues when parsing IDManifests +- added patches + CVE-2026-88384: NULL pointer dereference in the C++ attribute parsing path when a specially crafted EXR file containing an unknown-type attribute with dataSize set to zero is processed [bsc#1282700] + * openexr-CVE-2026-88384.patch + +------------------------------------------------------------------- Old: ---- v3.4.14.tar.gz New: ---- openexr-CVE-2026-88384.patch v3.4.15.tar.gz ----------(New B)---------- New: CVE-2026-88384: NULL pointer dereference in the C++ attribute parsing path when a specially crafted EXR file containing an unknown-type attribute with dataSize set to zero is processed [bsc#1282700] * openexr-CVE-2026-88384.patch ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ openexr.spec ++++++ --- /var/tmp/diff_new_pack.G4gKiT/_old 2026-09-30 16:23:09.885632940 +0200 +++ /var/tmp/diff_new_pack.G4gKiT/_new 2026-09-30 16:23:09.887633024 +0200 @@ -26,7 +26,7 @@ %endif Name: openexr -Version: 3.4.14 +Version: 3.4.15 Release: 0 Summary: Utilities for working with HDR images in OpenEXR format License: BSD-3-Clause @@ -34,6 +34,8 @@ URL: https://www.openexr.com/ Source0: https://github.com/AcademySoftwareFoundation/openexr/archive/v%{version}.tar.gz Source2: baselibs.conf +# CVE-2026-88384: NULL pointer dereference in the C++ attribute parsing path when a specially crafted EXR file containing an unknown-type attribute with dataSize set to zero is processed [bsc#1282700] +Patch0: openexr-CVE-2026-88384.patch BuildRequires: cmake >= 3.12 BuildRequires: freeglut-devel BuildRequires: gcc%{?force_gcc_version} ++++++ openexr-CVE-2026-88384.patch ++++++ >From e782bcc1ffe1cc9edfaa5dbad4f28e866eaf9bbb Mon Sep 17 00:00:00 2001 From: peterhillman <[email protected]> Date: Wed, 2 Sep 2026 07:09:54 +1200 Subject: [PATCH] check for dataSize==0 before memcpy in OpaqueAttribute (#2615) Signed-off-by: Peter Hillman <[email protected]> Co-authored-by: Cary Phillips <[email protected]> --- src/lib/OpenEXR/ImfOpaqueAttribute.cpp | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/src/lib/OpenEXR/ImfOpaqueAttribute.cpp b/src/lib/OpenEXR/ImfOpaqueAttribute.cpp index 1c0cf175c..b58083c3f 100644 --- a/src/lib/OpenEXR/ImfOpaqueAttribute.cpp +++ b/src/lib/OpenEXR/ImfOpaqueAttribute.cpp @@ -32,7 +32,8 @@ OpaqueAttribute::OpaqueAttribute (const char typeName[], : _typeName (typeName), _dataSize (dataSize) { _data.resizeErase (dataSize); - memcpy ((char*) _data, (const char*) data, dataSize); + if (dataSize>0) + memcpy ((char*) _data, (const char*) data, dataSize); } OpaqueAttribute::OpaqueAttribute (const OpaqueAttribute& other) @@ -41,7 +42,8 @@ OpaqueAttribute::OpaqueAttribute (const OpaqueAttribute& other) , _data (other._dataSize) { _data.resizeErase (other._dataSize); - memcpy ((char*) _data, (const char*) other._data, other._dataSize); + if (other._dataSize>0) + memcpy ((char*) _data, (const char*) other._data, other._dataSize); } OpaqueAttribute::~OpaqueAttribute () @@ -97,7 +99,8 @@ OpaqueAttribute::copyValueFrom (const Attribute& other) _data.resizeErase (oa->_dataSize); _dataSize = oa->_dataSize; - memcpy ((char*) _data, (const char*) oa->_data, oa->_dataSize); + if (oa->_dataSize>0) + memcpy ((char*) _data, (const char*) oa->_data, oa->_dataSize); } OPENEXR_IMF_INTERNAL_NAMESPACE_SOURCE_EXIT ++++++ v3.4.14.tar.gz -> v3.4.15.tar.gz ++++++ /work/SRC/openSUSE:Factory/openexr/v3.4.14.tar.gz /work/SRC/openSUSE:Factory/.openexr.new.1465845/v3.4.15.tar.gz differ: char 13, line 1
