[packages/OpenImageIO] - updated to 3.1.17.0 (fixes CVE-2026-67549 CVE-2026-65970 CVE-2026-63420 CVE-2026-63635 CVE-2026-63

qboosh qboosh at pld-linux.org
Wed Sep 16 19:41:53 CEST 2026


commit d620b27e3d1c8bc527de1460f5ea72cd252f6a23
Author: Jakub Bogusz <qboosh at pld-linux.org>
Date:   Wed Sep 16 19:42:04 2026 +0200

    - updated to 3.1.17.0 (fixes CVE-2026-67549 CVE-2026-65970 CVE-2026-63420 CVE-2026-63635 CVE-2026-63419 CVE-2026-65969 CVE-2026-63422 CVE-2026-63638)

 OpenImageIO-system-libcineon.patch |  8 +++----
 OpenImageIO.spec                   | 44 +++++++++++++++++++-------------------
 no-clang-format.patch              |  8 +++----
 plugins-link.patch                 | 13 -----------
 4 files changed, 30 insertions(+), 43 deletions(-)
---
diff --git a/OpenImageIO.spec b/OpenImageIO.spec
index 431d5d8..02c2b89 100644
--- a/OpenImageIO.spec
+++ b/OpenImageIO.spec
@@ -16,7 +16,7 @@
 %bcond_without	ocio		# OpenColorIO support in library
 %bcond_without	opencv		# OpenCV support in library
 %bcond_without	openvdb		# OpenVDB plugin
-%bcond_with	qt6		# Qt6 instead of Qt5
+%bcond_with	qt5		# Qt5 instead of Qt6
 %bcond_without	tbb		# Threading Building Blocks
 #
 %ifarch i386 i486
@@ -33,31 +33,30 @@
 Summary:	Library for reading and writing images
 Summary(pl.UTF-8):	Biblioteka do odczytu i zapisu obrazów
 Name:		OpenImageIO
-Version:	3.1.7.0
-Release:	5
+Version:	3.1.17.0
+Release:	1
 License:	Apache v2.0
 Group:		Libraries
 #Source0Download: https://github.com/AcademySoftwareFoundation/OpenImageIO/releases
 Source0:	https://github.com/AcademySoftwareFoundation/OpenImageIO/archive/v%{version}/%{name}-%{version}.tar.gz
-# Source0-md5:	951527a755911320659d4e23bb8e5ad9
-Patch1:		plugins-link.patch
+# Source0-md5:	6129ccf733f6cc6c9d14550d3765d9af
 Patch2:		%{name}-system-libcineon.patch
 Patch3:		no-clang-format.patch
 URL:		https://github.com/AcademySoftwareFoundation/OpenImageIO
 BuildRequires:	Imath-devel >= 3.1
 %{?with_ocio:BuildRequires:	OpenColorIO-devel >= 2.3}
-BuildRequires:	OpenEXR-devel >= 3.1
+BuildRequires:	OpenEXR-devel >= 3.1.10
 BuildRequires:	OpenGL-devel
-%if %{with qt6}
-BuildRequires:	Qt6Core-devel >= 6
-BuildRequires:	Qt6Gui-devel >= 6
-BuildRequires:	Qt6OpenGLWidgets-devel >= 6
-BuildRequires:	Qt6Widgets-devel >= 6
-%else
+%if %{with qt5}
 BuildRequires:	Qt5Core-devel >= 5.6
 BuildRequires:	Qt5Gui-devel >= 5.6
 BuildRequires:	Qt5OpenGL-devel >= 5.6
 BuildRequires:	Qt5Widgets-devel >= 5.6
+%else
+BuildRequires:	Qt6Core-devel >= 6
+BuildRequires:	Qt6Gui-devel >= 6
+BuildRequires:	Qt6OpenGL-devel >= 6
+BuildRequires:	Qt6Widgets-devel >= 6
 %endif
 # filesystem, regex, system, thread
 BuildRequires:	boost-devel >= 1.66
@@ -72,20 +71,22 @@ BuildRequires:	glew-devel >= 1.5.1
 BuildRequires:	hdf5-devel
 BuildRequires:	jasper-devel
 BuildRequires:	libcineon-devel
+BuildRequires:	libdeflate-devel >= 1.18
 BuildRequires:	libfmt-devel >= 9.0
-BuildRequires:	libheif-devel >= 1.16
+BuildRequires:	libheif-devel >= 1.17
 BuildRequires:	libjpeg-turbo-devel >= 2.1
 BuildRequires:	libjxl-devel >= 0.10.1
 BuildRequires:	libpng-devel >= 2:1.6.0
-BuildRequires:	libraw-devel >= 0.20
+BuildRequires:	libraw-devel >= 0.21.3
 BuildRequires:	libstdc++-devel >= 6:7
-BuildRequires:	libtiff-devel >= 4.0
+BuildRequires:	libtiff-devel >= 4.5
 BuildRequires:	libultrahdr-devel >= 1.3
 BuildRequires:	libwebp-devel >= 1.6.0-4
 %{?with_opencv:BuildRequires:	opencv-devel >= 4.0}
 BuildRequires:	openjpeg2-devel >= 2.4
 BuildRequires:	openjph-devel >= 0.21.2
 %{?with_openvdb:BuildRequires:	openvdb-devel >= 9.0}
+BuildRequires:	pkgconfig
 BuildRequires:	ptex-devel >= 2.1
 BuildRequires:	pugixml-devel >= 1.8
 BuildRequires:	python3-devel >= 1:3.7
@@ -97,7 +98,7 @@ BuildRequires:	squish-devel >= 1.10
 %{?with_tbb:BuildRequires:	tbb-devel >= 2018}
 BuildRequires:	txt2man
 BuildRequires:	zlib-devel
-Requires:	OpenEXR >= 3.1
+Requires:	OpenEXR >= 3.1.10
 Obsoletes:	OpenImageIO-plugin-field3d < 2.4
 BuildRoot:	%{tmpdir}/%{name}-%{version}-root-%(id -u -n)
 
@@ -220,7 +221,7 @@ Summary:	HEIF plugin for OpenImageIO library
 Summary(pl.UTF-8):	Wtyczka HEIF dla biblioteki OpenImageIO
 Group:		Libraries
 Requires:	%{name} = %{version}-%{release}
-Requires:	libheif >= 1.16
+Requires:	libheif >= 1.17
 
 %description plugin-heif
 OpenImageIO plugin to read HEIF files.
@@ -286,7 +287,7 @@ Summary:	OpenEXR plugin for OpenImageIO library
 Summary(pl.UTF-8):	Wtyczka OpenEXR dla biblioteki OpenImageIO
 Group:		Libraries
 Requires:	%{name} = %{version}-%{release}
-Requires:	OpenEXR >= 3.1
+Requires:	OpenEXR >= 3.1.10
 
 %description plugin-openexr
 OpenImageIO plugin to read and write OpenEXR files.
@@ -349,7 +350,7 @@ Summary:	RAW plugin for OpenImageIO library
 Summary(pl.UTF-8):	Wtyczka RAW dla biblioteki OpenImageIO
 Group:		Libraries
 Requires:	%{name} = %{version}-%{release}
-Requires:	libraw >= 0.20
+Requires:	libraw >= 0.21.3
 
 %description plugin-raw
 OpenImageIO plugin to readTRAW files.
@@ -374,7 +375,7 @@ Summary:	TIFF plugin for OpenImageIO library
 Summary(pl.UTF-8):	Wtyczka TIFF dla biblioteki OpenImageIO
 Group:		Libraries
 Requires:	%{name} = %{version}-%{release}
-Requires:	libtiff >= 4.0
+Requires:	libtiff >= 4.5
 
 %description plugin-tiff
 OpenImageIO plugin to read and write TIFF files.
@@ -417,7 +418,6 @@ Wiązanie Pythona do biblioteki OpenImageIO.
 
 %prep
 %setup -q
-%patch -P1 -p1
 %patch -P2 -p1
 %patch -P3 -p1
 
@@ -433,7 +433,7 @@ Wiązanie Pythona do biblioteki OpenImageIO.
 	-DSTOP_ON_WARNING=OFF \
 	%{!?with_ocio:-DUSE_OCIO=OFF} \
 	%{!?with_opencv:-DUSE_OPENCV=OFF} \
-	%{!?with_qt6:-DUSE_QT6=OFF} \
+	%{?with_qt5:-DUSE_QT6=OFF} \
 	%{!?with_tbb:-DUSE_TBB=OFF}
 
 %{__make} -C build
diff --git a/OpenImageIO-system-libcineon.patch b/OpenImageIO-system-libcineon.patch
index 2b5d71b..1835d31 100644
--- a/OpenImageIO-system-libcineon.patch
+++ b/OpenImageIO-system-libcineon.patch
@@ -11,8 +11,8 @@
  
  # Note: OIIO doesn't support cineon output, so we don't compile
  # libcineon/Writer.cpp
---- oiio-2.4.14.0/src/cineon.imageio/cineoninput.cpp.orig	2023-08-01 22:15:24.000000000 +0200
-+++ oiio-2.4.14.0/src/cineon.imageio/cineoninput.cpp	2023-08-22 17:46:26.265122755 +0200
+--- OpenImageIO-3.1.17.0/src/cineon.imageio/cineoninput.cpp.orig	2026-08-31 04:40:40.000000000 +0200
++++ OpenImageIO-3.1.17.0/src/cineon.imageio/cineoninput.cpp	2026-09-16 17:22:15.821626586 +0200
 @@ -4,7 +4,7 @@
  
  #include <cmath>
@@ -21,8 +21,8 @@
 +#include <Cineon.h>
  
  #include <OpenImageIO/dassert.h>
- #include <OpenImageIO/imageio.h>
-@@ -337,8 +337,8 @@ CineonInput::open(const std::string& nam
+ #include <OpenImageIO/filesystem.h>
+@@ -368,8 +368,8 @@ CineonInput::open(const std::string& nam
          // FIXME: do something about the time zone
      }
      {
diff --git a/no-clang-format.patch b/no-clang-format.patch
index cf624c2..bf64926 100644
--- a/no-clang-format.patch
+++ b/no-clang-format.patch
@@ -1,11 +1,11 @@
---- oiio-2.4.14.0/src/cmake/compiler.cmake.orig	2023-08-21 21:27:17.401404166 +0200
-+++ oiio-2.4.14.0/src/cmake/compiler.cmake	2023-08-21 21:28:41.787613674 +0200
-@@ -508,7 +508,7 @@ endif ()
+--- OpenImageIO-3.1.17.0/src/cmake/compiler.cmake.orig	2026-08-31 04:40:40.000000000 +0200
++++ OpenImageIO-3.1.17.0/src/cmake/compiler.cmake	2026-09-16 17:34:03.126544318 +0200
+@@ -585,7 +585,7 @@ endif ()
  #
  # Note: skip all of this checking, setup, and cmake-format target if this
  # is being built as a subproject.
 -if (PROJECT_IS_TOP_LEVEL)
 +if (FALSE)
      set (CLANG_FORMAT_EXE_HINT "" CACHE PATH "clang-format executable's directory (will search if not specified")
-     set (CLANG_FORMAT_INCLUDES "src/*.h" "src/*.cpp testsuite/*.cpp testsuite/*.h"
+     set (CLANG_FORMAT_INCLUDES "src/*.h" "src/*.cpp" "testsuite/*.cpp" "testsuite/*.h"
          CACHE STRING "Glob patterns to include for clang-format")
diff --git a/plugins-link.patch b/plugins-link.patch
deleted file mode 100644
index a9476d9..0000000
--- a/plugins-link.patch
+++ /dev/null
@@ -1,13 +0,0 @@
---- OpenImageIO-3.1.7.0/src/cmake/add_oiio_plugin.cmake~	2025-11-01 07:47:41.000000000 +0100
-+++ OpenImageIO-3.1.7.0/src/cmake/add_oiio_plugin.cmake	2025-11-30 12:53:31.556655652 +0100
-@@ -76,8 +76,8 @@
-                                         OpenImageIO_EXPORTS)
-             target_compile_options (${_plugin_NAME} PRIVATE ${_plugin_COMPILE_OPTIONS})
-             target_include_directories (${_plugin_NAME} BEFORE PRIVATE ${_plugin_INCLUDE_DIRS})
--            target_link_directories (${_plugin_NAME} PUBLIC OpenImageIO
--                                                     PRIVATE ${_plugin_LINK_DIRECTORIES})
-+#            target_link_directories (${_plugin_NAME} PUBLIC OpenImageIO
-+#                                                     PRIVATE ${_plugin_LINK_DIRECTORIES})
-             target_link_libraries (${_plugin_NAME} PUBLIC OpenImageIO
-                                                    PRIVATE ${_plugin_LINK_LIBRARIES})
-             set_target_properties (${_plugin_NAME} PROPERTIES PREFIX "" FOLDER "Plugins")
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/OpenImageIO.git/commitdiff/d620b27e3d1c8bc527de1460f5ea72cd252f6a23



More information about the pld-cvs-commit mailing list