[CLSA-2026:1785335342] openexr: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-29 14:29:13 UTC
Description:
- CVE-2026-34380: fix signed 32-bit integer overflow in the PXR24 decoder bounds check, where (uint64_t) (w * 3) wrapped to a small positive value and allowed an out-of-bounds write through dout - CVE-2026-34378: fix signed 32-bit integer overflow in srcbuffer pointer arithmetic in the unpack_* routines, reached via an oversized dataWindow width
Updated packages:
  • openexr-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
    sha:f3d4e1b32e3e64f4cb20e132bc5b62e311713a06cca9f84ebf161f09bf932e05
  • openexr-devel-3.1.1-3.el9.tuxcare.els9.i686.rpm
    sha:7dbbc7a30def7f573eed4a91fdaee688591febf24b4d3dd03f5479f2748264af
  • openexr-devel-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
    sha:b3d33307d997dd74eea26ed27d0b97233509400e2425bcc6c043cc289110d8d1
  • openexr-libs-3.1.1-3.el9.tuxcare.els9.i686.rpm
    sha:6a3c78052f12f5c6551c0d087f0e044e831c0b4d99f8ef51d45d1adeb1da7899
  • openexr-libs-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
    sha:23654276ee85a1d77710ea4110c50b519ffc9bd861df97686bd81db6d49c0525
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.