OpenEXR
High dynamic range image file format and library for visual effects
A second IDManifest flaw lands two weeks after OpenEXR's forty-CVE sweep
◆Recent moves
- 7h ago
3.3.14 backports the IDManifest memory fixes to the 3.3 stream
The 3.3-stream backport of the same two IDManifest memory-allocation fixes, tagged an hour after the 3.4 release and carrying its note verbatim — the body names v3.4.15 rather than its own version, and omits the Windows export and compiler-warning items specific to 3.4. Same multi-branch simultaneous-patch discipline as the 2026-08-05 sweep.
View source ↗ - 8h ago
3.4.15 fixes two IDManifest memory-allocation flaws
Two memory issues in IDManifest parsing, where corrupt or malicious input could trigger excessive allocation; CVEs are requested but not yet assigned. Scope is deliberately bounded — only idmanifest decoding is affected, and the notes state other code is safe even on files carrying the attribute. Also fixes a missing Windows export and trims compiler warnings in the example code.
View source ↗ - 14d ago
3.4.14 fixes 15 CVEs found by fuzzing the .exr parser
The largest of the three coordinated 2026-08-05 tags: 15 CVEs plus broader hardening from a single fuzzing and audit effort, spanning PyOpenEXR channel coalescing, 32-bit integer overflows, and the command-line tools. Establishes the response pattern the IDManifest fixes now follow.
View source ↗ - 14d ago
3.3.13 backports the same 15 CVE fixes to the 3.3 stream
The 3.3-stream twin of v3.4.14, tagged in the same minute with the same 15 CVE fixes and near-identical notes. Backporting the full set rather than a subset is what makes the 3.3 line a viable target for integrators who cannot move to 3.4.
View source ↗ - 14d ago
3.2.11 carries 10 of the CVE fixes to the oldest supported stream
The oldest supported stream received 10 of the CVE fixes, a smaller set than its siblings — consistent with 3.2 predating some of the affected code rather than being partially patched. Completes the three-branch simultaneous release.
View source ↗ - 2mo ago
3.3.12-rc updates CI install scripts
A CI install-script update with a sign-off line as its entire body — build-infrastructure maintenance with no user-visible change. Notable only as the last tag before the security work began.
View source ↗