Backport several OpenEXRCore security fixes Fixes CVE-2026-34378 / GHSA-v76p-4qvv-vh4g; closes RHBZ#2455493 Fixes CVE-2026-34380 / GHSA-q3v8-hw4m-59w5; closes RHBZ#2455534 Fixes CVE-2026-34588 / GHSA-588r-cr5c-w6hf; closes RHBZ#2455505 Fixes CVE-2026-34589 / GHSA-p8xc-w3q4-h64x; closes RHBZ#2455501. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-cde75a1416 2026-04-18 00:52:25.911654+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 43 Version : 25.08 Release : 20.fc43 URL : http://www.openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: Backport several OpenEXRCore security fixes Fixes CVE-2026-34378 / GHSA-v76p-4qvv-vh4g; closes RHBZ#2455493 Fixes CVE-2026-34380 / GHSA-q3v8-hw4m-59w5; closes RHBZ#2455534 Fixes CVE-2026-34588 / GHSA-588r-cr5c-w6hf; closes RHBZ#2455505 Fixes CVE-2026-34589 / GHSA-p8xc-w3q4-h64x; closes RHBZ#2455501 Fixes CVE-2026-34379 / GHSA-w88v-vqhq-5p24; closes RHBZ#2455497 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Benjamin A. Beasley - 25.08-20 - Backport several OpenEXRCore security fixes - Fixes CVE-2026-34378 / GHSA-v76p-4qvv-vh4g; closes RHBZ#2455493 - Fixes CVE-2026-34380 / GHSA-q3v8-hw4m-59w5; closes RHBZ#2455534 - Fixes CVE-2026-34588 / GHSA-588r-cr5c-w6hf; closes RHBZ#2455505 - Fixes CVE-2026-34589 / GHSA-p8xc-w3q4-h64x; closes RHBZ#2455501 - Fixes CVE-2026-34379 / GHSA-w88v-vqhq-5p24; closes RHBZ#2455497 * Tue Apr 7 2026 Benjamin A. Beasley - 25.08-19 - Backport fix for CVE-2026-34544 in OpenEXRCore - Fixes RHBZ#2454226 * Tue Apr 7 2026 Orion Poplawski -25.08-18 - Make devel require cmake(OpenSubdiv) and cmake(materialx) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455493 - CVE-2026-34378 usd: OpenEXR: Denial of Service via crafted EXR file integer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455493 [ 2 ] Bug #2455497 - CVE-2026-34379 usd: OpenEXR: Denial of Service due to misaligned memory write during EXR file decoding [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455497 [ 3 ] Bug #2455501 - CVE-2026-34589 usd: OpenEXR: Memory corruption leading to arbitrary code execution or denial of service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455501 [ 4 ] Bug #2455505 - CVE-2026-34588 usd: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455505 [ 5 ] Bug #2455534 - CVE-2026-34380 usd: OpenEXR: Denial of Service due to signed integer overflow in image decoding [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455534 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cde75a1416' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport fixes for CVE-2025-64181 etc. in OpenEXRCore . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-447047dda8 2025-12-16 01:13:25.255212+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 42 Version : 25.02a Release : 4.fc42 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: Backport fixes for CVE-2025-64181 etc. in OpenEXRCore -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Benjamin A. Beasley - 25.02a-4 - Backport fixes for CVE-2025-64181 etc. in OpenEXRCore -------------------------------------------------------------------------------- References: [ 1 ] Bug #2418251 - CVE-2025-64181 usd: Use of Uninitialized Memory inside generic_unpack [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418251 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-447047dda8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport fixes for CVE-2025-64181 etc. in OpenEXRCore. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4924a5bc8b 2025-12-16 00:46:10.314063+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 43 Version : 25.08 Release : 12.fc43 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: Backport fixes for CVE-2025-64181 etc. in OpenEXRCore -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- References: [ 1 ] Bug #2418252 - CVE-2025-64181 usd: Use of Uninitialized Memory inside generic_unpack [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2418252 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4924a5bc8b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.