RHSA-2026:69608HighCVSS 7.1

Red Hat Security Advisory: openexr security update

Published
September 22, 2026
Last Modified
September 22, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-68515 — OpenEXR: OpenEXR: Heap out-of-bounds write in exrmultiview via crafted EXR files

🎯 Affected products47

  • Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-0:3.1.1-3.el9_8.4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-0:3.1.1-3.el9_8.4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-0:3.1.1-3.el9_8.4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-0:3.1.1-3.el9_8.4.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-0:3.1.1-3.el9_8.4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.i686 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debuginfo-0:3.1.1-3.el9_8.4.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.i686 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • openexr-debugsource-0:3.1.1-3.el9_8.4.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-devel-0:3.1.1-3.el9_8.4.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-devel-0:3.1.1-3.el9_8.4.i686 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • openexr-devel-0:3.1.1-3.el9_8.4.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
  • +17 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, avoid processing untrusted or unverified EXR image files with the `exrmultiview` utility. Users should exercise caution when handling EXR files from unknown or suspicious sources. If possible, restrict the execution environment of `exrmultiview` through sandboxing mechanisms to limit potential impact.

🔗 References (4)