SB2026072260 - SUSE update for openexr



SB2026072260 - SUSE update for openexr

Published: July 22, 2026

Security Bulletin ID SB2026072260
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Integer overflow (CVE-ID: CVE-2026-54920)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in OpenEXRUtil Image::resize() and Image::clearLevels() when processing crafted Imath::Box2i data window coordinates through the public API. A remote attacker can supply crafted coordinate values that trigger exception cleanup and invalid deletion of uninitialized ImageLevel pointers to cause a denial of service.

The issue is confirmed to crash the process through an invalid delete of uninitialized pointer entries during exception cleanup, while remote code execution was not confirmed.


Remediation

Install update from vendor's website.