[CLSA-2026:1785425808] openexr: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-30 15:37:00 UTC
Description:
- CVE-2026-34380: fix signed 32-bit integer overflow in the PXR24 decoder bounds check, where (uint64_t) (w * 3) wrapped to a small positive value and allowed an out-of-bounds write through dout - CVE-2026-34378: fix signed 32-bit integer overflow in srcbuffer pointer arithmetic in the unpack_* routines, reached via an oversized dataWindow width
Updated packages:
  • openexr-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
    sha:0e64d3ff00e268f470c323baf7546bd90b93faff8c727ead66f3b58e2b8e858c
  • openexr-devel-3.1.1-3.el9.tuxcare.els9.i686.rpm
    sha:585ebeb6e12186057adaf83e5ef7a535583a89433af08d228581c5dcaa8a5e0c
  • openexr-devel-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
    sha:8aa3f3503c9eff3f7b858fe84a70c185f0a24a3c04bb5ed531b0b583b7f5a40e
  • openexr-libs-3.1.1-3.el9.tuxcare.els9.i686.rpm
    sha:927284216f9891d35da2c8b467566ec5323d89c4daa4c5f42cd7be5b44b16ca2
  • openexr-libs-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
    sha:545398813d7b8ef77e6d9160f432218a50b68a5bb837ee1da2868956f49f4aa5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.