Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
89

Fedora 44 OpenImageIO Security Advisory Allocation Size Bug 2026-25954ebccf

https://github.com/AcademySoftwareFoundation/OpenImageIO/releases/tag/v3.1.15.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-25954ebccf 2026-07-11 01:06:30.201222+00:00 -------------------------------------------------------------------------------- Name : OpenImageIO Product : Fedora 44 Version : 3.1.15.0 Release : 1.fc44 URL : https://openimageio.org/ Summary : Library for reading and writing images Description : OpenImageIO is a library for reading and writing images, and a bunch of related classes, utilities, and applications. Main features include: - Extremely simple but powerful ImageInput and ImageOutput APIs for reading and writing 2D images that is format agnostic. - Format plugins for TIFF, JPEG/JFIF, OpenEXR, PNG, HDR/RGBE, Targa, JPEG-2000, DPX, Cineon, FITS, BMP, ICO, RMan Zfile, Softimage PIC, DDS, SGI, PNM/PPM/PGM/PBM. - An ImageCache class that transparently manages a cache so that it can access truly vast amounts of image data. -------------------------------------------------------------------------------- Update Information: https://github.com/AcademySoftwareFoundation/OpenImageIO/releases/tag/v3.1.15.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 1 2026 Richard Shaw - 1:3.1.15.0-1 - Update to 3.1.15.0. * Thu Jun 25 2026 František Zatloukal - 1:3.1.14.0-6 - Rebuilt for fmt/spdlog * Wed Jun 17 2026 Yaakov Selkowitz - 1:3.1.14.0-5 - Rebuilt for openssl 4.0 * Wed Jun 17 2026 Simone Caronni - 1:3.1.14.0-4 - Rebuild for OpenJPH update. * Fri Jun 12 2026 Yaakov Selkowitz - 1:3.1.14.0-3 - Rebuilt for openssl 4.0 * Fri Jun 5 2026 Python Maint - 1:3.1.14.0-2 - Rebuilt for Python 3.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2341889 - CVE-2024-55195 OpenImageIO: An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2341889 [ 2 ] Bug #2341890 - CVE-2024-55195 OpenImageIO: An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2341890 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-25954ebccf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update OpenImageIO on Fedora 44 to resolve an allocation size issue. Ensure your system is secure and patched effectively.. OpenImageIO update, Fedora security, image library issue, software patching, allocation size bug. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2026 Important Fedora
172

Ubuntu OpenImageIO Significant Denial Of Service Security Flaws USN-8438-1

Several security issues were fixed in OpenImageIO.. ========================================================================== Ubuntu Security Notice USN-8438-1 June 16, 2026 openimageio vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenImageIO. Software Description: - openimageio: Library for reading and writing images Details: It was discovered that OpenImageIO incorrectly performed bounds checking when processing SGI files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-43903) It was discovered that OpenImageIO incorrectly handled run-length encoding when processing Softimage PIC files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-43904) It was discovered that OpenImageIO incorrectly validated subimage metadata when processing HEIF files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-43906) It was discovered that OpenImageIO contained multiple integer overflow vulnerabilities when processing DPX files. An attacker could possibly use these issues to cause a denial of service or execute arbitrary code. (CVE-2026-43907, CVE-2026-43908, CVE-2026-43909) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libopenimageio-dev 2.5.19.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro libopenimageio2.5 2.5.19.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro openimageio-tools 2.5.19.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro python3-openimageio 2.5.19.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS libopenimageio-dev 2.4.17.0+dfsg-1.1ubuntu0.1~esm1 Available with Ubuntu Pro libopenimageio2.4t64 2.4.17.0+dfsg-1.1ubuntu0.1~esm1 Available with Ubuntu Pro openimageio-tools 2.4.17.0+dfsg-1.1ubuntu0.1~esm1 Available with Ubuntu Pro python3-openimageio 2.4.17.0+dfsg-1.1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS libopenimageio-dev 2.1.12.0~dfsg0-1ubuntu0.1~esm1 Available with Ubuntu Pro libopenimageio2.1 2.1.12.0~dfsg0-1ubuntu0.1~esm1 Available with Ubuntu Pro openimageio-tools 2.1.12.0~dfsg0-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-openimageio 2.1.12.0~dfsg0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libopenimageio-dev 1.7.17~dfsg0-1ubuntu2+esm1 Available with Ubuntu Pro libopenimageio1.7 1.7.17~dfsg0-1ubuntu2+esm1 Available with Ubuntu Pro openimageio-tools 1.7.17~dfsg0-1ubuntu2+esm1 Available with Ubuntu Pro python-openimageio 1.7.17~dfsg0-1ubuntu2+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libopenimageio-dev 1.6.11~dfsg0-1ubuntu1+esm2 Available with Ubuntu Pro libopenimageio1.6 1.6.11~dfsg0-1ubuntu1+esm2 Available with Ubuntu Pro openimageio-tools 1.6.11~dfsg0-1ubuntu1+esm2 Available with Ubuntu Pro python-openimageio 1.6.11~dfsg0-1ubuntu1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8438-1 CVE-2026-43903, CVE-2026-43904, CVE-2026-43906, CVE-2026-43907, CVE-2026-43908, CVE-2026-43909 . Security advisory for Ubuntu OpenImageIO addresses critical issues and provides essential updates to ensure system integrity.. OpenImageIO updates Ubuntu security patch Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 16, 2026 Important Ubuntu
203

Mageia 9 OpenImageIO Critical Out-of-Bounds Write CVE-2026-7582

Security update. Publication date: 13 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0206.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-7582 Description: AcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write. (CVE-2026-7582) References: - https://bugs.mageia.org/show_bug.cgi?id=35536 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/7R7GIDPDUYRWVCXVSSQU525T3WNVPZ3N/ - https://www.cve.org/CVERecord?id=CVE-2026-7582 SRPMS: - 9/core/openimageio-2.4.10.0-1.1.mga9 . Security update for Mageia addressing CVE-2026-7582 in OpenImageIO due to out-of-bounds write risk.. Mageia OpenImageIO security update CVE-2026-7582 out-of-bounds. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 12, 2026 Important Mageia
202

openSUSE Tumbleweed OpenImageIO Safety Advisory CVE-2026-7582 2026-10752-1

An update that solves one vulnerability can now be installed.. # OpenImageIO-3.1.13.1-2.1 on GA media Announcement ID: openSUSE-SU-2026:10752-1 Rating: moderate Cross-References: * CVE-2026-7582 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the OpenImageIO-3.1.13.1-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * OpenImageIO 3.1.13.1-2.1 * OpenImageIO-devel 3.1.13.1-2.1 * libOpenImageIO3_1 3.1.13.1-2.1 * libOpenImageIO_Util3_1 3.1.13.1-2.1 * python3-OpenImageIO 3.1.13.1-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-7582.html . An important update for OpenImageIO on openSUSE Tumbleweed addresses a moderate vulnerability in the software.. OpenImageIO Update, openSUSE Tumbleweed Security, moderate Threat Resolution. . LinuxSecurity.com Team

Calendar%202 May 13, 2026 OpenSUSE
89

Fedora 44 OpenImageIO Denial of Service Vulnerability CVE-2026-5318

LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bef0050737 2026-04-13 21:06:00.498961+00:00 -------------------------------------------------------------------------------- Name : OpenImageIO Product : Fedora 44 Version : 3.1.12.0 Release : 2.fc44 URL : https://openimageio.org/ Summary : Library for reading and writing images Description : OpenImageIO is a library for reading and writing images, and a bunch of related classes, utilities, and applications. Main features include: - Extremely simple but powerful ImageInput and ImageOutput APIs for reading and writing 2D images that is format agnostic. - Format plugins for TIFF, JPEG/JFIF, OpenEXR, PNG, HDR/RGBE, Targa, JPEG-2000, DPX, Cineon, FITS, BMP, ICO, RMan Zfile, Softimage PIC, DDS, SGI, PNM/PPM/PGM/PBM. - An ImageCache class that transparently manages a cache so that it can access truly vast amounts of image data. -------------------------------------------------------------------------------- Update Information: LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0) IBA: Handle offset data windows in fillholes_pushpull #5105 (3.1.12.0, 3.0.17.0) ImageInput: check_open fixes and new validity checks #5087 (3.1.12.0, 3.0.17.0) bmp: Use check_open to guard against corrupt resolutions #5086 (3.1.12.0, 3.0.17.0) heif: Fix invalid read writing 8-bit images with dimensions not a multiple of 64 #5095 (by Brecht Van Lommel) ico: Various validity checks anderror handling for corruptions #5088 (3.1.12.0, 3.0.17.0) jpeg: Improved safety and error reporting for jpeg and iptc #5081 jpeg2000: Suppress leak when reading with OpenJPH #5098 psd: Fixes against corrupt files with better validation #5089 (3.1.12.0, 3.0.17.0) rla: Lots of additional validity checking and safety #5094 (3.1.12.0, 3.0.17.0) tiff: Support GPS fields, and other metadata enhancements #5050 tiff: Fix buffer overrun and improve error reporting #5082, fix wrong number of values passed to invert_photometric #5083, check for invalid bit depth in palette images #5091 ImageSpec: metadata_val improved safety #5096 (3.1.12.0, 3.0.17.0) fix: Fix UB-sanitizer warning about alignment #5097 fix: Catch exceptions in print-uncaught-messages destructor #5103 fix: Enhanced exception safety for our use of OpenColorIO #5114 fix: Fix possible fmt exceptions where we might have passed null string #5115 build: Test building with clang 22.1, fix warnings uncovered #5067 build: Improve security by pinning auto-build dependencies by hash #5076 build: Include idiff in the python wheels we build #5104 (3.1.12.0, 3.0.17.0) build(pybind11): Address new pybind11 float/int auto-conversion behavior #5058 build(win): Embed manifest in OIIO executables to enable long path handling #5066 (by Nathan Rusch) ci: Add CI test for MSVS 2026 #5060 (3.1.12.0, 3.0.17.0) ci: For security, replace workflow substitutions with safer env substitutions #5070 ci: Speed up slow benchmarks for debug and sanitizer CI tests #5077 ci: On Mac Intel CI variant, don't install openvdb, for speed #5065 (3.1.12.0, 3.0.17.0) ci: Bump GitHub Actions to latest versions #5078 #5110 #5119 ci: Fix broken Mac CI and wheel building by specifying full compiler paths #5100 #5101 (3.1.12.0, 3.0.17.0) ci: Update certificates to be able to install icc #5122 (3.1.12.0, 3.0.17.0) ci: Turn off nightly workflows for user forks #5042 tests: New ref outputs for tiff-misc, heif no-avif, and ffmpeg 8.1 cases #5075 #5079 #5099 #5112 docs: Updatedescription for dwaCompressionLevel #5074 (by Aamir Raza) docs: Fix formatting examples for version macros #5073 docs: Keep TextureSystem docs in sync with ImageCache #5085 (3.1.12.0, 3.0.17.0) docs: Fix typos and incorrect attribute name in a comment #5093 (3.1.12.0, 3.0.17.0) docs: Fix misstatement about oiiotool --if #5102 (3.1.12.0, 3.0.17.0) admin: Draft policy on use of AI coding assistants #5072 (3.1.12.0, 3.0.17.0) ci: Freetype adjustments #4999 Update to 5.1 (#2451401) Update to 5.0 (#2447841) -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Gwyn Ciesla - 1:3.1.12.0-2 - Libraw rebuild * Sat Apr 4 2026 Richard Shaw - 1:3.1.12.0-1 - Update to 3.1.12.0. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447841 - swayimg-.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447841 [ 2 ] Bug #2451401 - swayimg-5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2451401 [ 3 ] Bug #2454235 - CVE-2026-5318 LibRaw: LibRaw: Denial of Service via out-of-bounds write in JPEG DHT Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454235 [ 4 ] Bug #2454464 - CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454464 [ 5 ] Bug #2455346 - LibRaw-0.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2455346 [ 6 ] Bug #2456557 - CVE-2026-20884 LibRaw: LibRaw: Arbitrary code execution via integer overflow in deflate_dng_load_raw [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456557 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bef0050737' at the command line. For more information, refer to the dnf documentationavailable at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update for OpenImageIO in Fedora 44 addresses critical images library issues related to security and performance.. OpenImageIO Fedora Update Denial of Service Image Processing. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Critical Fedora
91

Gentoo: GLSA-202506-09 normal: OpenImageIO multiple issues

Multiple vulnerabilities have been discovered in OpenImageIO, the worst of which can lead to execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202506-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: OpenImageIO: Multiple Vulnerabilities Date: June 12, 2025 Bugs: #903807, #917679 ID: 202506-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in OpenImageIO, the worst of which can lead to execution of arbitrary code. Background ========== OpenImageIO is a library for reading and writing images. Affected packages ================= Package Vulnerable Unaffected ---------------------- ------------ ------------ media-libs/openimageio < 2.5.4.0 > = 2.5.4.0 Description =========== Multiple vulnerabilities have been discovered in OpenImageIO. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All OpenImageIO users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/openimageio-2.5.4.0" References ========== [ 1 ] CVE-2023-22845 https://nvd.nist.gov/vuln/detail/CVE-2023-22845 [ 2 ] CVE-2023-24472 https://nvd.nist.gov/vuln/detail/CVE-2023-24472 [ 3 ] CVE-2023-24473 https://nvd.nist.gov/vuln/detail/CVE-2023-24473 [ 4 ] CVE-2023-36183 https://nvd.nist.gov/vuln/detail/CVE-2023-36183 [ 5 ] CVE-2023-42295 https://nvd.nist.gov/vuln/detail/CVE-2023-42295 [ 6 ] CVE-2023-42299 https://nvd.nist.gov/vuln/detail/CVE-2023-42299 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202506-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2025 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . OpenImageIO has encountered several security issues, the most critical of which may allow remote code execution. It is advisable to apply updates promptly.. Gentoo OpenImageIO vulnerabilities patch. . LinuxSecurity.com Team

Calendar%202 Jun 12, 2025 Gentoo
197

Debian: DLA-3518-1 Moderate: OpenImageIO DoS Threat Overview

Multiple security vulnerabilities have been discovered in OpenImageIO, a library for reading and writing images. Buffer overflows and out-of-bounds read and write programming errors may lead to a denial of service (application crash) or the execution of arbitrary code if a malformed image . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3518-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany August 07, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : openimageio Version : 2.0.5~dfsg0-1+deb10u2 CVE ID : CVE-2022-41649 CVE-2022-41684 CVE-2022-41794 CVE-2022-41837 CVE-2023-24472 CVE-2023-36183 Debian Bug : 1027143 1034151 Multiple security vulnerabilities have been discovered in OpenImageIO, a library for reading and writing images. Buffer overflows and out-of-bounds read and write programming errors may lead to a denial of service (application crash) or the execution of arbitrary code if a malformed image file is processed. For Debian 10 buster, these problems have been fixed in version 2.0.5~dfsg0-1+deb10u2. We recommend that you upgrade your openimageio packages. For the detailed security status of openimageio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openimageio Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade OpenImageIO software packages on Debian to rectify critical buffer overflow and denial of service security vulnerabilities.. OpenImageIO Security Update, Debian LTS Advisory, Buffer Overflow Fix. . LinuxSecurity.com Team

Calendar%202 Aug 06, 2023 Debian LTS
203

Mageia: 2023-0151 Critical: OpenImageIO Heap Out-Of-Bounds Issues

A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. (CVE-2022-36354) . MGASA-2023-0151 - Updated openimageio packages fix security vulnerability Publication date: 24 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0151.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-36354, CVE-2022-38143, CVE-2022-41639, CVE-2022-41684, CVE-2022-41794, CVE-2022-41838, CVE-2022-41977, CVE-2022-41981, CVE-2022-41988, CVE-2022-41999, CVE-2022-43592, CVE-2022-43593, CVE-2022-43594, CVE-2022-43595, CVE-2022-43596, CVE-2022-43597, CVE-2022-43598, CVE-2022-43599, CVE-2022-43600, CVE-2022-43601, CVE-2022-43602, CVE-2022-43603, CVE-2023-22845, CVE-2023-24472, CVE-2023-24473 A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. (CVE-2022-36354) A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. (CVE-2022-38143) A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. (CVE-2022-41639) A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsingthe image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. (CVE-2022-41684) A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. (CVE-2022-41794) A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer overflow. (CVE-2022-41838) An out of bounds read vulnerability exists in the way OpenImageIO version v2.3.19.0 processes string fields in TIFF image files. A specially-crafted TIFF file can lead to information disclosure. (CVE-2022-41977) A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-crafted targa file can lead to out of bounds read and write on the process stack, which can lead to arbitrary code execution. (CVE-2022-41981) An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0. A specially-crafted TIFF file can lead to a disclosure of sensitive information. (CVE-2022-41988) A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. (CVE-2022-41999) An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. (CVE-2022-43592) A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. (CVE-2022-43593) Multiple denial of service vulnerabilities exist in the image output closingfunctionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. This vulnerability applies to writing .bmp files. (CVE-2022-43594) Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. This vulnerability applies to writing .fits files. (CVE-2022-43595) An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. (CVE-2022-43596) Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to arbitrary code execution. This vulnerability arises when the 'm_spec.format' is 'TypeDesc::UINT8'. (CVE-2022-43597) Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to arbitrary code execution. This vulnerability arises when the 'm_spec.format' is 'TypeDesc::UINT16'. (CVE-2022-43598) Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. This vulnerability arises when the 'xmax' variable is set to 0xFFFF and 'm_spec.format' is 'TypeDesc::UINT8'. (CVE-2022-43599) Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. This vulnerability arises when the 'xmax' variable is set to 0xFFFF and 'm_spec.format' is 'TypeDesc::UINT16'. (CVE-2022-43600) Multiple codeexecution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. This vulnerability arises when the 'ymax' variable is set to 0xFFFF and 'm_spec.format' is 'TypeDesc::UINT16'. (CVE-2022-43601) Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. This vulnerability arises when the 'ymax' variable is set to 0xFFFF and 'm_spec.format' is 'TypeDesc::UINT8'. (CVE-2022-43602) A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to denial of service. (CVE-2022-43603) An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. (CVE-2023-22845) A denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted ImageOutput Object can lead to denial of service. (CVE-2023-24472) An information disclosure vulnerability exists in the TGAInput::read_tga2_header functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to a disclosure of sensitive information. (CVE-2023-24473) References: - https://bugs.mageia.org/show_bug.cgi?id=31364 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/T3LET4MEPBSBJZK4EMLEBY4FUXKU5BMN/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/MLUXEL7AB2S5ACSDCHG67GEZHUYZBR5O/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/LK6TY36VQ3FQXMZ2VXHZGQ43VDLD67GG/ -https://lists.debian.org/debian-lts-announce/2023/04/msg00004.html - https://lists.debian.org/debian-security-announce/2023/msg00074.html - https://www.cve.org/CVERecord?id=CVE-2022-36354 - https://www.cve.org/CVERecord?id=CVE-2022-38143 - https://www.cve.org/CVERecord?id=CVE-2022-41639 - https://www.cve.org/CVERecord?id=CVE-2022-41684 - https://www.cve.org/CVERecord?id=CVE-2022-41794 - https://www.cve.org/CVERecord?id=CVE-2022-41838 - https://www.cve.org/CVERecord?id=CVE-2022-41977 - https://www.cve.org/CVERecord?id=CVE-2022-41981 - https://www.cve.org/CVERecord?id=CVE-2022-41988 - https://www.cve.org/CVERecord?id=CVE-2022-41999 - https://www.cve.org/CVERecord?id=CVE-2022-43592 - https://www.cve.org/CVERecord?id=CVE-2022-43593 - https://www.cve.org/CVERecord?id=CVE-2022-43594 - https://www.cve.org/CVERecord?id=CVE-2022-43595 - https://www.cve.org/CVERecord?id=CVE-2022-43596 - https://www.cve.org/CVERecord?id=CVE-2022-43597 - https://www.cve.org/CVERecord?id=CVE-2022-43598 - https://www.cve.org/CVERecord?id=CVE-2022-43599 - https://www.cve.org/CVERecord?id=CVE-2022-43600 - https://www.cve.org/CVERecord?id=CVE-2022-43601 - https://www.cve.org/CVERecord?id=CVE-2022-43602 - https://www.cve.org/CVERecord?id=CVE-2022-43603 - https://www.cve.org/CVERecord?id=CVE-2023-22845 - https://www.cve.org/CVERecord?id=CVE-2023-24472 - https://www.cve.org/CVERecord?id=CVE-2023-24473 SRPMS: - 8/core/openimageio-2.2.10.0-1.1.mga8 . Mageia 2023-0151 tackles severe OpenImageIO security flaws, enhancing both system security and overall stability.. OpenImageIO Security, Mageia Update, Critical Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 24, 2023 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200