Red Hat Product Errata RHSA-2026:39024 - Security Advisory Issued: 2026-07-13 Updated: 2026-07-13 RHSA-2026:39024 - Security Advisory Overview Updated Packages Synopsis Important: openexr security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for openexr is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description OpenEXR is an open-source high-dynamic-range floating-point image file format for high-quality image processing and storage. This document presents a brief overview of OpenEXR and explains concepts that are specific to this format. This package containes the binaries for OpenEXR. Security Fix(es): OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing (CVE-2026-41142) OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files (CVE-2026-42216) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2467623 - CVE-2026-41142 OpenEXR: OpenEXR: Arbitrary code execution via integer overflow in image resizing BZ - 2467633 - CVE-2026-42216 OpenEXR: OpenEXR: Information disclosure and denial of service via malformed EXR files CVEs CVE-2026-41142 CVE-2026-42216 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM openexr-3.1.10-8.el10_0.3.src.rpm SHA-256: 78ec4c2ace02be9b224d7da4265b8b5f7039d9f02cc2e0ed2591f1efa1a9057d x86_64 openexr-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 41c914dd83e64dbf7944d286917c0234dddcada0f5a817a070217ee2ad65f905 openexr-debuginfo-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 1e7e63ff37f523ce45ad1ef5a286b5a3d36e01049dbcfd063a55d6de50b5f688 openexr-debugsource-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 9c70a93e835f35d241b2ce61a70ca24433f630af886d03bbcb262e3c176a5ba9 openexr-libs-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 0d7fc1d28706879d240743be776a05c72b8fdf3b435d992e06f495c76095deb2 openexr-libs-debuginfo-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 4ec5e07e1c07f0653d7a536941db1dbf4fd7161c853521221ac8218b6b7eb09c Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM openexr-3.1.10-8.el10_0.3.src.rpm SHA-256: 78ec4c2ace02be9b224d7da4265b8b5f7039d9f02cc2e0ed2591f1efa1a9057d s390x openexr-3.1.10-8.el10_0.3.s390x.rpm SHA-256: c19d202b12adec5e6623856a18a8fbad37f777862e613c6a6a5a49bdc08a4d3e openexr-debuginfo-3.1.10-8.el10_0.3.s390x.rpm SHA-256: 4abc34ca3cc0c5f7a58b8d1f79c4edf0bc6358cac87b10b34e8af22d257c198c openexr-debugsource-3.1.10-8.el10_0.3.s390x.rpm SHA-256: 7e719ec91affe6c919391f3737f6c3863bd126b12c962f6e018bdeca7eec982f openexr-libs-3.1.10-8.el10_0.3.s390x.rpm SHA-256: c2ea581fbdaef00fc2a8b97d83cc9dc2c0cc328b505d12f8c59508b1343d78b5 openexr-libs-debuginfo-3.1.10-8.el10_0.3.s390x.rpm SHA-256: 3ff92092e68e45d1d9ed27c129f90165ccfc8ef771cd1d45652bc7dec2589e00 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM openexr-3.1.10-8.el10_0.3.src.rpm SHA-256: 78ec4c2ace02be9b224d7da4265b8b5f7039d9f02cc2e0ed2591f1efa1a9057d ppc64le openexr-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: f705702b7c7855573a3ff7ad6e4572c5794012a29e086fe182539bf3c601014c openexr-debuginfo-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: cebdef5812249a51b19b219a6fbcd57f8c5b02bb91e67f6f3a3355c659f076dd openexr-debugsource-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: eb57ae98a4df816a8fa2bbf76116feb1d08096ae28f8e2ed01b2a0699ff1e688 openexr-libs-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: ab992132b61fc1a3994aa44b94d97999bea76d9d5d4302098b5868d78bc9b669 openexr-libs-debuginfo-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: d256cdc1191858b9bd7dc722827f4a2b4f4cfd32f446f273053200f07e5137e4 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM openexr-3.1.10-8.el10_0.3.src.rpm SHA-256: 78ec4c2ace02be9b224d7da4265b8b5f7039d9f02cc2e0ed2591f1efa1a9057d aarch64 openexr-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: c92e1072bb0e2f6ccb4bef680dad2ef0af6168061a4c996007039be85d87db78 openexr-debuginfo-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 46e5c5297d75b137d351ac5d07c89f01cdc36d25e86f89588c6258421faddb32 openexr-debugsource-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 28a90b846a5d4b99e90f3215fcd0fd334d857cc21b22106de20bfa8d9609aeaa openexr-libs-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 4848b79165d4ef06e82f306ce9f50b674c9cee650e3f5cb8da8df0a1c66dccc1 openexr-libs-debuginfo-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 49adf34f0a9220aaa8764a2c380832161acd41230885b99cde43afd218849974 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.0 SRPM x86_64 openexr-debuginfo-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 1e7e63ff37f523ce45ad1ef5a286b5a3d36e01049dbcfd063a55d6de50b5f688 openexr-debugsource-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 9c70a93e835f35d241b2ce61a70ca24433f630af886d03bbcb262e3c176a5ba9 openexr-devel-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 61bae90cbd88eb0f48c6abd5b76a56ba9cae91067004024d5d5239f602edd019 openexr-libs-debuginfo-3.1.10-8.el10_0.3.x86_64.rpm SHA-256: 4ec5e07e1c07f0653d7a536941db1dbf4fd7161c853521221ac8218b6b7eb09c Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.0 SRPM ppc64le openexr-debuginfo-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: cebdef5812249a51b19b219a6fbcd57f8c5b02bb91e67f6f3a3355c659f076dd openexr-debugsource-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: eb57ae98a4df816a8fa2bbf76116feb1d08096ae28f8e2ed01b2a0699ff1e688 openexr-devel-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: 63963e8482bd0dfe57fb4ad251794bed4540b49f5876df5cabb999e500a80541 openexr-libs-debuginfo-3.1.10-8.el10_0.3.ppc64le.rpm SHA-256: d256cdc1191858b9bd7dc722827f4a2b4f4cfd32f446f273053200f07e5137e4 Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.0 SRPM s390x openexr-debuginfo-3.1.10-8.el10_0.3.s390x.rpm SHA-256: 4abc34ca3cc0c5f7a58b8d1f79c4edf0bc6358cac87b10b34e8af22d257c198c openexr-debugsource-3.1.10-8.el10_0.3.s390x.rpm SHA-256: 7e719ec91affe6c919391f3737f6c3863bd126b12c962f6e018bdeca7eec982f openexr-devel-3.1.10-8.el10_0.3.s390x.rpm SHA-256: b8d2abf5f4975e441824781c97bf45b6d6aa49208a28ebcbd85b690781c72e95 openexr-libs-debuginfo-3.1.10-8.el10_0.3.s390x.rpm SHA-256: 3ff92092e68e45d1d9ed27c129f90165ccfc8ef771cd1d45652bc7dec2589e00 Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.0 SRPM aarch64 openexr-debuginfo-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 46e5c5297d75b137d351ac5d07c89f01cdc36d25e86f89588c6258421faddb32 openexr-debugsource-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 28a90b846a5d4b99e90f3215fcd0fd334d857cc21b22106de20bfa8d9609aeaa openexr-devel-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 7f9a5d5c6413f1c5646cefada3a5ea383ba71ef8417801f7215f6500696a161f openexr-libs-debuginfo-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 49adf34f0a9220aaa8764a2c380832161acd41230885b99cde43afd218849974 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM openexr-3.1.10-8.el10_0.3.src.rpm SHA-256: 78ec4c2ace02be9b224d7da4265b8b5f7039d9f02cc2e0ed2591f1efa1a9057d aarch64 openexr-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: c92e1072bb0e2f6ccb4bef680dad2ef0af6168061a4c996007039be85d87db78 openexr-debuginfo-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 46e5c5297d75b137d351ac5d07c89f01cdc36d25e86f89588c6258421faddb32 openexr-debugsource-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 28a90b846a5d4b99e90f3215fcd0fd334d857cc21b22106de20bfa8d9609aeaa openexr-libs-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 4848b79165d4ef06e82f306ce9f50b674c9cee650e3f5cb8da8df0a1c66dccc1 openexr-libs-debuginfo-3.1.10-8.el10_0.3.aarch64.rpm SHA-256: 49adf34f0a9220aaa8764a2c380832161acd41230885b99cde43afd218849974 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 SRPM openexr-3.1.10-8.el10_0.3.src.rpm SHA-256: 78ec4c2ace02be9b224d7da4265b8b5f7039d9f02cc2e0ed2591f1efa1a9057d s390x openexr-3.1.10-8.el10_0.3.s390x.rpm SHA-256: c19d202b12adec5e6623856a18a8fbad37f777862e613c6a6a5a49bdc08a4d3e openexr-debuginfo-3.1.10-8.el10_0.3.s390x.rpm SHA-256: 4abc34ca3cc0c5f7a58b8d1f79c4edf0bc6358cac87b10b34e8af22d257c198c openexr-debugsource-3.1.10-8.el10_0.3.s390x.rpm SHA-256: 7e719ec91affe6c919391f3737f6c3863bd126b12c962f6e018bdeca7eec982f openexr-libs-3.1.10-8.el10_0.3.s390x.rpm SHA-256: c2ea581fbdaef00fc2a8b97d83cc9dc2c0cc328b505d12f8c59508b1343d78b5 openexr-libs-debuginfo-3.1.10-8.el10_0.3.s390x.rpm SH
Two critical vulnerabilities in OpenEXR (CVE-2026-41142 and CVE-2026-42216) allow arbitrary code execution via an integer overflow during image resizing and information disclosure/denial of service via malformed EXR files, respectively. The CVSS scores are 8.8 (High) and 9.1 (Critical). Affected versions are openexr 3.0.0 through 3.2.8, 3.3.0 through 3.3.10, and 3.4.0 through 3.4.10; users must upgrade to versions 3.2.9, 3.3.11, or 3.4.11 to remediate.