OpenEXR
High dynamic range image file format and library for visual effects
One fuzzing campaign, forty CVEs, and every supported OpenEXR branch patched at once
◆Recent moves
- 5d ago
3.4.14 fixes 15 CVEs found by fuzzing the .exr parser
The current-line member of the coordinated security release: 15 CVEs plus broader hardening, nearly all memory corruption reachable by opening a crafted .exr file through the libraries, the exr command-line tools, or the Python bindings. The most consequential of the three, since it covers the branch new work sits on.
View source ↗ - 5d ago
3.3.13 backports the same 15 CVE fixes to the 3.3 stream
Identical remediation scoped to the v3.3 release stream, tagged seconds apart from the 3.4 release. Its existence is the point — studios pinned to 3.3 get the same fixes without a minor-version migration.
View source ↗ - 5d ago
3.2.11 carries 10 of the CVE fixes to the oldest supported stream
The 3.2 stream receives 10 of the CVEs rather than the full 15, reflecting which code paths exist on that branch. Completes a three-branch simultaneous patch of every supported line.
View source ↗ - 1mo ago
3.3.12-rc updates CI install scripts
A CI-only change with a one-line body and no user-facing effect, tagged six weeks before the security batch. Build plumbing.
View source ↗