Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2e7d5d49f2 2026-01-03 01:15:48.095284+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 42 Version : 25.02a Release : 5.fc42 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442 -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 25 2025 Benjamin A. Beasley - 25.02a-5 - Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442 (fix RHBZ#2422275) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2422275 - CVE-2025-14439 usd: OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2422275 [ 2 ] Bug #2424910 - CVE-2025-12839 usd: OpenEXR: Remote Code Execution via Heap-based Buffer Overflow in EXR File Parsing [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424910 [ 3 ] Bug #2424912 - CVE-2025-12840 usd: OpenEXR: Remote Code Execution via EXR file parsing heap-based buffer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424912 [ 4 ] Bug #2424917 - CVE-2025-12495 usd: OpenEXR: Remote Code Execution via malicious EXR file parsing [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424917 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-2e7d5d49f2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f882263432 2026-01-02 00:38:59.597974+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 43 Version : 25.08 Release : 13.fc43 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 24 2025 Benjamin A. Beasley - 25.08-13 - Backport fix for CVE-2025-14439/GHSA-grjp-54v3-c442 (fix RHBZ#2422276) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2422276 - CVE-2025-14439 usd: OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2422276 [ 2 ] Bug #2424922 - CVE-2025-12839 usd: OpenEXR: Remote Code Execution via Heap-based Buffer Overflow in EXR File Parsing [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424922 [ 3 ] Bug #2424924 - CVE-2025-12840 usd: OpenEXR: Remote Code Execution via EXR file parsing heap-based buffer overflow [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424924 [ 4 ] Bug #2424926 - CVE-2025-12495 usd: OpenEXR: Remote Code Execution via malicious EXR file parsing [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424926 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-f882263432' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
PySide6 6.10.1 update. Pyside6 6.10.1 release. Rebuilt with stb_image patched for two new security bugs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-0cc929ff17 2025-12-04 00:51:14.440721+00:00 -------------------------------------------------------------------------------- Name : usd Product : Fedora 43 Version : 25.08 Release : 11.fc43 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. -------------------------------------------------------------------------------- Update Information: PySide6 6.10.1 update. Pyside6 6.10.1 release. Rebuilt with stb_image patched for two new security bugs. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Jan Grulich - 25.08-11 - Rebuild (python-pyside6) * Tue Nov 25 2025 Benjamin A. Beasley - 25.08-10 - Correct minimum NVR for stb_image * Tue Nov 25 2025 Benjamin A. Beasley - 25.08-9 - Rebuilt with stb_image patched for two new security bugs * Tue Nov 25 2025 Benjamin A. Beasley - 25.08-7 - Add direct build dependency on OpenCL as a workaround * Tue Sep 30 2025 Luya Tshimbalanga - 25.08-6 - Rebuild for openvdb 12.1.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2400455 - python-pyside6-6.10.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2400455 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0cc929ff17' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fix for CVE-2022-28041. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-61f6ee6353 2022-05-01 19:39:06.906407 --------------------------------------------------------------------------------Name : usd Product : Fedora 35 Version : 21.11 Release : 11.fc35 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-28041 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 20 2022 Benjamin A. Beasley 21.11-11 - Security fix for CVE-2022-28041 --------------------------------------------------------------------------------References: [ 1 ] Bug #2077054 - Rebuild usd with updated stb_image-{devel,static} for CVE-2022-28041 https://bugzilla.redhat.com/show_bug.cgi?id=2077054 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-61f6ee6353' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-28021, CVE-2021-42715, CVE-2021-42716, and CVE-2022-28041. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-832689aa6b 2022-04-29 06:56:10.869253 --------------------------------------------------------------------------------Name : usd Product : Fedora 34 Version : 21.08 Release : 19.fc34 URL : https://openusd.org/ Summary : 3D VFX pipeline interchange file format Description : Universal Scene Description (USD) is a time-sampled scene description for interchange between graphics applications. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-28021, CVE-2021-42715, CVE-2021-42716, and CVE-2022-28041 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 20 2022 Benjamin A. Beasley 21.08-19 - Security fix for CVE-2022-28041 * Wed Apr 20 2022 Benjamin A. Beasley 21.08-18 - Move bundled library virtual Provides to -libs * Wed Apr 20 2022 Benjamin A. Beasley 21.08-17 - Patch CVE-2021-28021, CVE-2021-42715, and CVE-2021-42716 * Wed Apr 20 2022 Benjamin A. Beasley 21.08-16 - Add comments explaining where to find versions for bundled deps --------------------------------------------------------------------------------References: [ 1 ] Bug #2077054 - Rebuild usd with updated stb_image-{devel,static} for CVE-2022-28041 https://bugzilla.redhat.com/show_bug.cgi?id=2077054 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-832689aa6b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Projectcan be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.