Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 38: 2023-d486d13cfd Critical Memory Access Issues

fedora
Calendar Grey November 4, 2023
Dist Fedora Esm H88
Essential patch addressing various vulnerabilities in the usd library for Fedora 38, improving overall system resilience and protection.
Security fix for CVE-2023-45661 CVE-2023-45662 CVE-2023-45663 CVE-2023-45664 CVE-2023-45666 CVE-2023-45667 CVE-2023-45675 CVE-2023-43281

Summary

Universal Scene Description (USD) is a time-sampled scene

description for interchange between graphics applications.

Update Information:

Security fix for CVE-2023-45661 CVE-2023-45662 CVE-2023-45663 CVE-2023-45664 CVE-2023-45666 CVE-2023-45667 CVE-2023-45675 CVE-2023-43281

Change Log

* Thu Oct 26 2023 Benjamin A. Beasley - 22.05b-39 - Ensure stb_image contains the latest CVE patches * Thu Oct 26 2023 Benjamin A. Beasley - 22.05b-38 - Add versioned Requires on usd-libs from python3-usd

References


[ 1 ] Bug #2246102 - CVE-2023-45661 stb: out of bounds read https://bugzilla.redhat.com/show_bug.cgi?id=2246102 [ 2 ] Bug #2246103 - CVE-2023-45662 stb: out of bounds read https://bugzilla.redhat.com/show_bug.cgi?id=2246103 [ 3 ] Bug #2246104 - CVE-2023-45663 stb: memory access violations https://bugzilla.redhat.com/show_bug.cgi?id=2246104 [ 4 ] Bug #2246105 - CVE-2023-45664 stb: memory access violations https://bugzilla.redhat.com/show_bug.cgi?id=2246105 [ 5 ] Bug #2246109 - CVE-2023-45666 stb: memory access violation https://bugzilla.redhat.com/show_bug.cgi?id=2246109 [ 6 ] Bug #2246110 - CVE-2023-45667 stb: memory access violation https://bugzilla.redhat.com/show_bug.cgi?id=2246110 [ 7 ] Bug #2246320 - CVE-2023-43281 stb: remote denial of service https://bugzilla.redhat.com/show_bug.cgi?id=2246320

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d486d13cfd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: usd
Product: Fedora 38
Version: 22.05b
Release: 39.fc38
Summary: 3D VFX pipeline interchange file format

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here