Release date:
2026-07-30 15:37:00 UTC
Description:
- CVE-2026-34380: fix signed 32-bit integer overflow in the PXR24 decoder
bounds check, where (uint64_t) (w * 3) wrapped to a small positive value
and allowed an out-of-bounds write through dout
- CVE-2026-34378: fix signed 32-bit integer overflow in srcbuffer pointer
arithmetic in the unpack_* routines, reached via an oversized dataWindow
width
Updated packages:
-
openexr-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
sha:0e64d3ff00e268f470c323baf7546bd90b93faff8c727ead66f3b58e2b8e858c
-
openexr-devel-3.1.1-3.el9.tuxcare.els9.i686.rpm
sha:585ebeb6e12186057adaf83e5ef7a535583a89433af08d228581c5dcaa8a5e0c
-
openexr-devel-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
sha:8aa3f3503c9eff3f7b858fe84a70c185f0a24a3c04bb5ed531b0b583b7f5a40e
-
openexr-libs-3.1.1-3.el9.tuxcare.els9.i686.rpm
sha:927284216f9891d35da2c8b467566ec5323d89c4daa4c5f42cd7be5b44b16ca2
-
openexr-libs-3.1.1-3.el9.tuxcare.els9.x86_64.rpm
sha:545398813d7b8ef77e6d9160f432218a50b68a5bb837ee1da2868956f49f4aa5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.