Release date:
2026-07-29 14:29:13 UTC
Description:
- CVE-2026-34380: fix signed 32-bit integer overflow in the PXR24 decoder
bounds check, where (uint64_t) (w * 3) wrapped to a small positive value
and allowed an out-of-bounds write through dout
- CVE-2026-34378: fix signed 32-bit integer overflow in srcbuffer pointer
arithmetic in the unpack_* routines, reached via an oversized dataWindow
width
Updated packages:
-
openexr-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
sha:f3d4e1b32e3e64f4cb20e132bc5b62e311713a06cca9f84ebf161f09bf932e05
-
openexr-devel-3.1.1-3.el9.tuxcare.els9.i686.rpm
sha:7dbbc7a30def7f573eed4a91fdaee688591febf24b4d3dd03f5479f2748264af
-
openexr-devel-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
sha:b3d33307d997dd74eea26ed27d0b97233509400e2425bcc6c043cc289110d8d1
-
openexr-libs-3.1.1-3.el9.tuxcare.els9.i686.rpm
sha:6a3c78052f12f5c6551c0d087f0e044e831c0b4d99f8ef51d45d1adeb1da7899
-
openexr-libs-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
sha:23654276ee85a1d77710ea4110c50b519ffc9bd861df97686bd81db6d49c0525
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.