Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 37: A93C06A1D9 Critical: USD Memory Access Issues

fedora
Calendar Grey November 4, 2023
Dist Fedora Esm H88
Critical patch addressing various memory access vulnerabilities and denial of service threats in usd for Fedora 37. Please update your systems immediately.
Security fix for CVE-2023-45661 CVE-2023-45662 CVE-2023-45663 CVE-2023-45664 CVE-2023-45666 CVE-2023-45667 CVE-2023-45675 CVE-2023-43281

Summary

Universal Scene Description (USD) is a time-sampled scene

description for interchange between graphics applications.

Update Information:

Security fix for CVE-2023-45661 CVE-2023-45662 CVE-2023-45663 CVE-2023-45664 CVE-2023-45666 CVE-2023-45667 CVE-2023-45675 CVE-2023-43281

Change Log

* Thu Oct 26 2023 Benjamin A. Beasley - 22.05b-28 - Ensure stb_image contains the latest CVE patches * Thu Oct 26 2023 Benjamin A. Beasley - 22.05b-27 - Add versioned Requires on usd-libs from python3-usd * Thu Oct 26 2023 Benjamin A. Beasley - 22.05b-26 - Update License to SPDX

References


[ 1 ] Bug #2246102 - CVE-2023-45661 stb: out of bounds read https://bugzilla.redhat.com/show_bug.cgi?id=2246102 [ 2 ] Bug #2246103 - CVE-2023-45662 stb: out of bounds read https://bugzilla.redhat.com/show_bug.cgi?id=2246103 [ 3 ] Bug #2246104 - CVE-2023-45663 stb: memory access violations https://bugzilla.redhat.com/show_bug.cgi?id=2246104 [ 4 ] Bug #2246105 - CVE-2023-45664 stb: memory access violations https://bugzilla.redhat.com/show_bug.cgi?id=2246105 [ 5 ] Bug #2246109 - CVE-2023-45666 stb: memory access violation https://bugzilla.redhat.com/show_bug.cgi?id=2246109 [ 6 ] Bug #2246110 - CVE-2023-45667 stb: memory access violation https://bugzilla.redhat.com/show_bug.cgi?id=2246110 [ 7 ] Bug #2246320 - CVE-2023-43281 stb: remote denial of service https://bugzilla.redhat.com/show_bug.cgi?id=2246320

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a93c06a1d9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: usd
Product: Fedora 37
Version: 22.05b
Release: 28.fc37
Summary: 3D VFX pipeline interchange file format

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here