github AcademySoftwareFoundation/openexr v3.2.9

latest releases: v3.4.11, v3.3.11
2 hours ago

Patch release for 3.2 that addresses the following security vulnerabilities:

  • CVE-2026-42217 Shift exponent overflow in readVariableLengthInteger() (ImfIDManifest.cpp)

  • CVE-2026-42216 Out-of-bounds read in IDManifest::init() during prefix expansion

  • CVE-2026-41142 Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API

  • OSS-fuzz 504280155 Heap-buffer-overflow in DwaCompressor_uncompress

Don't miss a new openexr release

NewReleases is sending notifications on new releases.