Your message dated Sat, 22 Aug 2026 11:04:38 +0000
with message-id <[email protected]>
and subject line Bug#1136001: fixed in openexr 3.4.14-0.1
has caused the Debian Bug report #1136001,
regarding openexr: CVE-2026-42216 CVE-2026-42217
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1136001: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136001
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: openexr
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security
Hi,
The following vulnerabilities were published for openexr.
CVE-2026-42216[0]:
| OpenEXR provides the specification and reference implementation of
| the EXR file format, an image storage format for the motion picture
| industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before
| 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs
| strings from a prefix-compressed representation. If the previous
| string is longer than 255 bytes, the next string is expected to
| begin with a 2-byte prefix length. The code reads stringList[i][0]
| and stringList[i][1] without checking that the current string has at
| least two bytes. This issue has been patched in versions 3.2.9,
| 3.3.11, and 3.4.11.
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-65j8-95g9-jgj4
CVE-2026-42217[1]:
| OpenEXR provides the specification and reference implementation of
| the EXR file format, an image storage format for the motion picture
| industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before
| 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger()
| decodes a variable-length integer from untrusted EXR input without
| bounding the shift count. After enough continuation bytes, the code
| executes a left shift by 70 on a 64-bit value, which is undefined
| behavior. This issue has been patched in versions 3.2.9, 3.3.11, and
| 3.4.11.
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3c67-4wwp-w52m
https://github.com/AcademySoftwareFoundation/openexr/pull/2378
Fixed by:
https://github.com/AcademySoftwareFoundation/openexr/commit/21eaa33bcbbb0c83a5fc42f6b6d65b70a996e63c
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-42216
https://www.cve.org/CVERecord?id=CVE-2026-42216
[1] https://security-tracker.debian.org/tracker/CVE-2026-42217
https://www.cve.org/CVERecord?id=CVE-2026-42217
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: openexr
Source-Version: 3.4.14-0.1
Done: Adrian Bunk <[email protected]>
We believe that the bug you reported is fixed in the latest version of
openexr, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Adrian Bunk <[email protected]> (supplier of updated openexr package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 20 Aug 2026 19:49:50 +0300
Source: openexr
Architecture: source
Version: 3.4.14-0.1
Distribution: unstable
Urgency: medium
Maintainer: Debian PhotoTools Maintainers
<[email protected]>
Changed-By: Adrian Bunk <[email protected]>
Closes: 1132578 1132579 1132580 1133188 1134642 1135946 1136001 1136879 1144763
1144878
Changes:
openexr (3.4.14-0.1) unstable; urgency=medium
.
* Non-maintainer upload.
* New upstream release. (Closes: #1136879)
- Fixes FTBFS with glibc 2.43. (Closes: #1144878)
- CVE-2026-34378: Signed integer overflow in generic_unpack()
- CVE-2026-34379: Misaligned write in LossyDctDecoder_execute
- CVE-2026-34380: Signed integer overflow in undo_pxr24_impl()
- CVE-2026-34588: Signed 32-bit Overflow in PIZ Decoder
- CVE-2026-34589: DWA Lossy Decoder Heap Out-of-Bounds Write
(Closes: #1133188)
- CVE-2026-34543: Heap information disclosure in PXR24 decompression
(Closes: #1132580)
- CVE-2026-34544: Integer overflow in uncompress_b44_impl()
(Closes: #1132579)
- CVE-2026-34545: Integer overflow in HTJ2K decoder
(Closes: #1132578)
- CVE-2026-39886: Signed Integer Overflow in ht_undo_impl()
- CVE-2026-40244: Integer overflow in DWA setupChannelData
- CVE-2026-40250: Integer overflow in DWA decoder
(Closes: #1134642)
- CVE-2026-41142: Integer overflow in ImageChannel::resize()
(Closes: #1135946)
- CVE-2026-42216: Out-of-bounds read in IDManifest::init()
- CVE-2026-42217: Shift exponent overflow in readVariableLengthInteger()
(Closes: #1136001)
- CVE-2026-44663: Integer overflow in HTJ2K decoder
- CVE-2026-45696: Heap buffer overflow in ht_undo_impl()
- CVE-2026-59183: Signed Integer Overflow in Deep Tile Decoding
- CVE-2026-59184: OpenEXRUtil FlatImageChannel row OOB write
- CVE-2026-59186: OpenEXR ILP32 TiledRgbaInputFile large tile OOB write
- CVE-2026-59187: OpenEXR exrmetrics deep pixelmode heap buffer overflow
- CVE-2026-59189: OpenEXRUtil DeepImageChannel heap OOB read
- CVE-2026-59981: OpenEXRUtil SampleCountChannel heap OOB read
- CVE-2026-59982: ILP32 DWAA InputFile packed AC buffer overflow
- CVE-2026-59983: ILP32 DeepTiledInputFile sample count table OOB read
- CVE-2026-59984: ILP32 B44 InputFile decode scratch buffer overflow
- CVE-2026-59985: ILP32 OpenEXRCore RLE decode heap OOB read DoS
- CVE-2026-61555: Empty multiView viewFromChannelName file crash
* Generate Provides that includes the Imath version and use in the shlibs.
(Closes: #1144763)
* Disable test that fails on armhf instead of ignoring all test failures
on armhf.
* Ignore test failures on all big endian architectures.
* Attempt to fix FTBFS on hurd-amd64.
* Ignore test failures on Hurd.
Checksums-Sha1:
4e1228f642baa3d056345996075470e88150a253 2261 openexr_3.4.14-0.1.dsc
c0bb14f1dfb0c9a6f2e38725397013ce9ce4d6b8 20598272 openexr_3.4.14.orig.tar.xz
674d0668a9d7ed5619bb34670cab2513dbd573cd 19384 openexr_3.4.14-0.1.debian.tar.xz
Checksums-Sha256:
30540eb3d46620be9aaed388d0c179d5846a890e94baf48e0f1650ca3cd4d7a7 2261
openexr_3.4.14-0.1.dsc
5bc1a561a418ac59b5c309e42820dda0e6f4c087f10b5cf8e30c4899c1d68f09 20598272
openexr_3.4.14.orig.tar.xz
d1f1929c2045562640f5c3cda3ef93ca49827e2ad91ae90fde243bd16a0aeeef 19384
openexr_3.4.14-0.1.debian.tar.xz
Files:
9d9256429c816c2e26a22ad778d85ed9 2261 graphics optional openexr_3.4.14-0.1.dsc
64216513dde4a579c60354b610bb4d6e 20598272 graphics optional
openexr_3.4.14.orig.tar.xz
e3937bbb7954bbf50ee6716787358e25 19384 graphics optional
openexr_3.4.14-0.1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmqIN2YACgkQiNJCh6LY
mLF8Wg//dkxGb0fDrFTms4t1AGU/RCsBLVseTT/5Uj19NA2QmRW0YmKTWDqXZocR
RtuvI68uXEfaQkyiqPu2NGN7vrKls/uRJWmzTHUSVl8/ZteRX1cV8gV7mNcVS2m2
8y3/QStwtI01hic95HJLSzowvj+Jf8vlwp/zehkS7fluzbdgrDJJ1vlhGuo29toO
mVNdxXXPGbXzL7ZiP6VsZERwwFcXoI0Z5I/79DzWECuksASnAepAK6G58IXR9On5
JPEvXnbSVGkOLupvXUnb+rDXjOGQaYaBwZdK1by2NMjXTFOHEv7iiZPJ8WG9jegv
mfC5ckP2trlpl3i7kn4wU6cpVprXF9mqcWrpcpdsylEUouNugyKhaExILqxu9/Sh
vXH7kmz88OckgvAUzJsjk8A4mt+BcW5KTXjufHUYf6sS+lfHMOBAH9NZ/yikLR40
J+TNd/q49Wgfdy6l5OCgYB+1py/ub7H+R8r3UGhUlqPjgnrVbKengIpxE+gBUFJf
bZz1OOQpP5D6tkK02B9XEC9rS0eY+8RTt+BkML+r02IoPoanbILOPl8h4KhSptC6
g84K0C5bp5Od9/szAENqXaWaRWjd71y9oULX4n/SYlQkD4co2VhAya7fGxl8zb/Q
FavZbrG3lhwRPOfupiNstpSJwkBYdC0/+3GVkV93Oi753mtEElU=
=5zjm
-----END PGP SIGNATURE-----
pgplKDaUaH2C9.pgp
Description: PGP signature
--- End Message ---