[packages/OpenImageIO] - updated to 3.1.17.0 (fixes CVE-2026-67549 CVE-2026-65970 CVE-2026-63420 CVE-2026-63635 CVE-2026-63
qboosh
qboosh at pld-linux.org
Wed Sep 16 19:41:53 CEST 2026
commit d620b27e3d1c8bc527de1460f5ea72cd252f6a23
Author: Jakub Bogusz <qboosh at pld-linux.org>
Date: Wed Sep 16 19:42:04 2026 +0200
- updated to 3.1.17.0 (fixes CVE-2026-67549 CVE-2026-65970 CVE-2026-63420 CVE-2026-63635 CVE-2026-63419 CVE-2026-65969 CVE-2026-63422 CVE-2026-63638)
OpenImageIO-system-libcineon.patch | 8 +++----
OpenImageIO.spec | 44 +++++++++++++++++++-------------------
no-clang-format.patch | 8 +++----
plugins-link.patch | 13 -----------
4 files changed, 30 insertions(+), 43 deletions(-)
---
diff --git a/OpenImageIO.spec b/OpenImageIO.spec
index 431d5d8..02c2b89 100644
--- a/OpenImageIO.spec
+++ b/OpenImageIO.spec
@@ -16,7 +16,7 @@
%bcond_without ocio # OpenColorIO support in library
%bcond_without opencv # OpenCV support in library
%bcond_without openvdb # OpenVDB plugin
-%bcond_with qt6 # Qt6 instead of Qt5
+%bcond_with qt5 # Qt5 instead of Qt6
%bcond_without tbb # Threading Building Blocks
#
%ifarch i386 i486
@@ -33,31 +33,30 @@
Summary: Library for reading and writing images
Summary(pl.UTF-8): Biblioteka do odczytu i zapisu obrazów
Name: OpenImageIO
-Version: 3.1.7.0
-Release: 5
+Version: 3.1.17.0
+Release: 1
License: Apache v2.0
Group: Libraries
#Source0Download: https://github.com/AcademySoftwareFoundation/OpenImageIO/releases
Source0: https://github.com/AcademySoftwareFoundation/OpenImageIO/archive/v%{version}/%{name}-%{version}.tar.gz
-# Source0-md5: 951527a755911320659d4e23bb8e5ad9
-Patch1: plugins-link.patch
+# Source0-md5: 6129ccf733f6cc6c9d14550d3765d9af
Patch2: %{name}-system-libcineon.patch
Patch3: no-clang-format.patch
URL: https://github.com/AcademySoftwareFoundation/OpenImageIO
BuildRequires: Imath-devel >= 3.1
%{?with_ocio:BuildRequires: OpenColorIO-devel >= 2.3}
-BuildRequires: OpenEXR-devel >= 3.1
+BuildRequires: OpenEXR-devel >= 3.1.10
BuildRequires: OpenGL-devel
-%if %{with qt6}
-BuildRequires: Qt6Core-devel >= 6
-BuildRequires: Qt6Gui-devel >= 6
-BuildRequires: Qt6OpenGLWidgets-devel >= 6
-BuildRequires: Qt6Widgets-devel >= 6
-%else
+%if %{with qt5}
BuildRequires: Qt5Core-devel >= 5.6
BuildRequires: Qt5Gui-devel >= 5.6
BuildRequires: Qt5OpenGL-devel >= 5.6
BuildRequires: Qt5Widgets-devel >= 5.6
+%else
+BuildRequires: Qt6Core-devel >= 6
+BuildRequires: Qt6Gui-devel >= 6
+BuildRequires: Qt6OpenGL-devel >= 6
+BuildRequires: Qt6Widgets-devel >= 6
%endif
# filesystem, regex, system, thread
BuildRequires: boost-devel >= 1.66
@@ -72,20 +71,22 @@ BuildRequires: glew-devel >= 1.5.1
BuildRequires: hdf5-devel
BuildRequires: jasper-devel
BuildRequires: libcineon-devel
+BuildRequires: libdeflate-devel >= 1.18
BuildRequires: libfmt-devel >= 9.0
-BuildRequires: libheif-devel >= 1.16
+BuildRequires: libheif-devel >= 1.17
BuildRequires: libjpeg-turbo-devel >= 2.1
BuildRequires: libjxl-devel >= 0.10.1
BuildRequires: libpng-devel >= 2:1.6.0
-BuildRequires: libraw-devel >= 0.20
+BuildRequires: libraw-devel >= 0.21.3
BuildRequires: libstdc++-devel >= 6:7
-BuildRequires: libtiff-devel >= 4.0
+BuildRequires: libtiff-devel >= 4.5
BuildRequires: libultrahdr-devel >= 1.3
BuildRequires: libwebp-devel >= 1.6.0-4
%{?with_opencv:BuildRequires: opencv-devel >= 4.0}
BuildRequires: openjpeg2-devel >= 2.4
BuildRequires: openjph-devel >= 0.21.2
%{?with_openvdb:BuildRequires: openvdb-devel >= 9.0}
+BuildRequires: pkgconfig
BuildRequires: ptex-devel >= 2.1
BuildRequires: pugixml-devel >= 1.8
BuildRequires: python3-devel >= 1:3.7
@@ -97,7 +98,7 @@ BuildRequires: squish-devel >= 1.10
%{?with_tbb:BuildRequires: tbb-devel >= 2018}
BuildRequires: txt2man
BuildRequires: zlib-devel
-Requires: OpenEXR >= 3.1
+Requires: OpenEXR >= 3.1.10
Obsoletes: OpenImageIO-plugin-field3d < 2.4
BuildRoot: %{tmpdir}/%{name}-%{version}-root-%(id -u -n)
@@ -220,7 +221,7 @@ Summary: HEIF plugin for OpenImageIO library
Summary(pl.UTF-8): Wtyczka HEIF dla biblioteki OpenImageIO
Group: Libraries
Requires: %{name} = %{version}-%{release}
-Requires: libheif >= 1.16
+Requires: libheif >= 1.17
%description plugin-heif
OpenImageIO plugin to read HEIF files.
@@ -286,7 +287,7 @@ Summary: OpenEXR plugin for OpenImageIO library
Summary(pl.UTF-8): Wtyczka OpenEXR dla biblioteki OpenImageIO
Group: Libraries
Requires: %{name} = %{version}-%{release}
-Requires: OpenEXR >= 3.1
+Requires: OpenEXR >= 3.1.10
%description plugin-openexr
OpenImageIO plugin to read and write OpenEXR files.
@@ -349,7 +350,7 @@ Summary: RAW plugin for OpenImageIO library
Summary(pl.UTF-8): Wtyczka RAW dla biblioteki OpenImageIO
Group: Libraries
Requires: %{name} = %{version}-%{release}
-Requires: libraw >= 0.20
+Requires: libraw >= 0.21.3
%description plugin-raw
OpenImageIO plugin to readTRAW files.
@@ -374,7 +375,7 @@ Summary: TIFF plugin for OpenImageIO library
Summary(pl.UTF-8): Wtyczka TIFF dla biblioteki OpenImageIO
Group: Libraries
Requires: %{name} = %{version}-%{release}
-Requires: libtiff >= 4.0
+Requires: libtiff >= 4.5
%description plugin-tiff
OpenImageIO plugin to read and write TIFF files.
@@ -417,7 +418,6 @@ Wiązanie Pythona do biblioteki OpenImageIO.
%prep
%setup -q
-%patch -P1 -p1
%patch -P2 -p1
%patch -P3 -p1
@@ -433,7 +433,7 @@ Wiązanie Pythona do biblioteki OpenImageIO.
-DSTOP_ON_WARNING=OFF \
%{!?with_ocio:-DUSE_OCIO=OFF} \
%{!?with_opencv:-DUSE_OPENCV=OFF} \
- %{!?with_qt6:-DUSE_QT6=OFF} \
+ %{?with_qt5:-DUSE_QT6=OFF} \
%{!?with_tbb:-DUSE_TBB=OFF}
%{__make} -C build
diff --git a/OpenImageIO-system-libcineon.patch b/OpenImageIO-system-libcineon.patch
index 2b5d71b..1835d31 100644
--- a/OpenImageIO-system-libcineon.patch
+++ b/OpenImageIO-system-libcineon.patch
@@ -11,8 +11,8 @@
# Note: OIIO doesn't support cineon output, so we don't compile
# libcineon/Writer.cpp
---- oiio-2.4.14.0/src/cineon.imageio/cineoninput.cpp.orig 2023-08-01 22:15:24.000000000 +0200
-+++ oiio-2.4.14.0/src/cineon.imageio/cineoninput.cpp 2023-08-22 17:46:26.265122755 +0200
+--- OpenImageIO-3.1.17.0/src/cineon.imageio/cineoninput.cpp.orig 2026-08-31 04:40:40.000000000 +0200
++++ OpenImageIO-3.1.17.0/src/cineon.imageio/cineoninput.cpp 2026-09-16 17:22:15.821626586 +0200
@@ -4,7 +4,7 @@
#include <cmath>
@@ -21,8 +21,8 @@
+#include <Cineon.h>
#include <OpenImageIO/dassert.h>
- #include <OpenImageIO/imageio.h>
-@@ -337,8 +337,8 @@ CineonInput::open(const std::string& nam
+ #include <OpenImageIO/filesystem.h>
+@@ -368,8 +368,8 @@ CineonInput::open(const std::string& nam
// FIXME: do something about the time zone
}
{
diff --git a/no-clang-format.patch b/no-clang-format.patch
index cf624c2..bf64926 100644
--- a/no-clang-format.patch
+++ b/no-clang-format.patch
@@ -1,11 +1,11 @@
---- oiio-2.4.14.0/src/cmake/compiler.cmake.orig 2023-08-21 21:27:17.401404166 +0200
-+++ oiio-2.4.14.0/src/cmake/compiler.cmake 2023-08-21 21:28:41.787613674 +0200
-@@ -508,7 +508,7 @@ endif ()
+--- OpenImageIO-3.1.17.0/src/cmake/compiler.cmake.orig 2026-08-31 04:40:40.000000000 +0200
++++ OpenImageIO-3.1.17.0/src/cmake/compiler.cmake 2026-09-16 17:34:03.126544318 +0200
+@@ -585,7 +585,7 @@ endif ()
#
# Note: skip all of this checking, setup, and cmake-format target if this
# is being built as a subproject.
-if (PROJECT_IS_TOP_LEVEL)
+if (FALSE)
set (CLANG_FORMAT_EXE_HINT "" CACHE PATH "clang-format executable's directory (will search if not specified")
- set (CLANG_FORMAT_INCLUDES "src/*.h" "src/*.cpp testsuite/*.cpp testsuite/*.h"
+ set (CLANG_FORMAT_INCLUDES "src/*.h" "src/*.cpp" "testsuite/*.cpp" "testsuite/*.h"
CACHE STRING "Glob patterns to include for clang-format")
diff --git a/plugins-link.patch b/plugins-link.patch
deleted file mode 100644
index a9476d9..0000000
--- a/plugins-link.patch
+++ /dev/null
@@ -1,13 +0,0 @@
---- OpenImageIO-3.1.7.0/src/cmake/add_oiio_plugin.cmake~ 2025-11-01 07:47:41.000000000 +0100
-+++ OpenImageIO-3.1.7.0/src/cmake/add_oiio_plugin.cmake 2025-11-30 12:53:31.556655652 +0100
-@@ -76,8 +76,8 @@
- OpenImageIO_EXPORTS)
- target_compile_options (${_plugin_NAME} PRIVATE ${_plugin_COMPILE_OPTIONS})
- target_include_directories (${_plugin_NAME} BEFORE PRIVATE ${_plugin_INCLUDE_DIRS})
-- target_link_directories (${_plugin_NAME} PUBLIC OpenImageIO
-- PRIVATE ${_plugin_LINK_DIRECTORIES})
-+# target_link_directories (${_plugin_NAME} PUBLIC OpenImageIO
-+# PRIVATE ${_plugin_LINK_DIRECTORIES})
- target_link_libraries (${_plugin_NAME} PUBLIC OpenImageIO
- PRIVATE ${_plugin_LINK_LIBRARIES})
- set_target_properties (${_plugin_NAME} PROPERTIES PREFIX "" FOLDER "Plugins")
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/OpenImageIO.git/commitdiff/d620b27e3d1c8bc527de1460f5ea72cd252f6a23
More information about the pld-cvs-commit
mailing list