graphics/openexr*: Security update 3.4.13 => 3.4.14
Changelog:
https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.14
PR: 297486
Reported by: mandree (maintainer)
Approved by: osa, vvd (Mentors, implicit)
Pull Request: https://github.com/freebsd/freebsd-ports/pull/580
MFH: 2026Q3
Security: CVE-2026-68514 PyOpenEXR deep prefixed literal RGB key collision heap buffer overflow
Security: CVE-2026-68513 PyOpenEXR prefixed literal RGB key collision heap buffer overflow
Security: CVE-2026-62986 PyOpenEXR deep prefixed RGB stale lane disclosure
Security: CVE-2026-61703 PyOpenEXR deep mixed RGB heap buffer overflow
Security: CVE-2026-61555 empty multiView viewFromChannelName file crash
Security: CVE-2026-59985 ILP32 OpenEXRCore RLE decode heap OOB read DoS
Security: CVE-2026-59984 ILP32 B44 InputFile decode scratch buffer overflow
Security: CVE-2026-59983 ILP32 DeepTiledInputFile sample count table decode OOB read
Security: CVE-2026-59982 ILP32 DWAA InputFile packed AC buffer overflow
Security: CVE-2026-59981 OpenEXRUtil SampleCountChannel row nonzero dataWindow heap OOB read
Security: CVE-2026-59189 OpenEXRUtil DeepImageChannel row nonzero dataWindow heap OOB read
Security: CVE-2026-59187 OpenEXR exrmetrics deep pixelmode heap buffer overflow
Security: CVE-2026-59186 OpenEXR ILP32 TiledRgbaInputFile large tile Array2D heap OOB write
Security: CVE-2026-59184 OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write
Security: CVE-2026-59183 Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Decoding
(cherry picked from commit 43e43009bbb057f5dbcd4351a7172e6fe4a2d7c1)