[Git][security-tracker-team/security-tracker][master] Track fixes for openexr via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 22 12:35:31 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e527bcc8 by Salvatore Bonaccorso at 2026-08-22T13:32:59+02:00
Track fixes for openexr via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -63687,7 +63687,7 @@ CVE-2026-47633 (Exposure of sensitive information to an unauthorized actor in Co
CVE-2026-46699 (conda-smithy is a tool for combining a conda recipe with configuration ...)
NOT-FOR-US: conda-smithy
CVE-2026-45696 (OpenEXR is the reference implementation and specification for the EXR ...)
- - openexr <unfixed>
+ - openexr 3.4.14-0.1
[trixie] - openexr <not-affected> (Vulnerable code not present)
[bookworm] - openexr <not-affected> (Vulnerable code not present)
[bullseye] - openexr <not-affected> (Vulnerable code not present)
@@ -63696,7 +63696,7 @@ CVE-2026-45696 (OpenEXR is the reference implementation and specification for th
NOTE: Introduced by https://github.com/AcademySoftwareFoundation/openexr/commit/50ba96b1dbe353a98a626c7fd0ff1e50cc8c188f (v3.4-alpha)
NOTE: Fixed by: by https://github.com/AcademySoftwareFoundation/openexr/commit/c7af2d233b7b2a4452c11f26cf47584cc2b35721 (v3.4.13-rc)
CVE-2026-44663 (OpenEXR is the reference implementation and specification for the EXR ...)
- - openexr <unfixed>
+ - openexr 3.4.14-0.1
[trixie] - openexr <not-affected> (Vulnerable code not present)
[bookworm] - openexr <not-affected> (Vulnerable code not present)
[bullseye] - openexr <not-affected> (Vulnerable code not present)
@@ -94190,12 +94190,12 @@ CVE-2026-43576 (OpenClaw before 2026.4.5 contains a server-side request forgery
CVE-2026-43575 (OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication ...)
NOT-FOR-US: OpenClaw
CVE-2026-42217 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1136001)
+ - openexr 3.4.14-0.1 (bug #1136001)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-3c67-4wwp-w52m
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2378
NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/21eaa33bcbbb0c83a5fc42f6b6d65b70a996e63c
CVE-2026-42216 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1136001)
+ - openexr 3.4.14-0.1 (bug #1136001)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-65j8-95g9-jgj4
CVE-2026-42194 (Admidio is an open-source user management solution. Prior to version 5 ...)
NOT-FOR-US: Admidio
@@ -94293,7 +94293,7 @@ CVE-2026-41201 (CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a prod
CVE-2026-41143 (YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWi ...)
NOT-FOR-US: YesWiki
CVE-2026-41142 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1135946)
+ - openexr 3.4.14-0.1 (bug #1135946)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m25w-72cj-q6mg
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2367
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/0592ee539f33c122c90f09238579b902d838afb4 (main)
@@ -104930,14 +104930,14 @@ CVE-2026-40279 (BACnet Stack is a BACnet open source protocol stack C library fo
CVE-2026-40264 (OpenBao is an open source identity-based secrets management system. Op ...)
- openbao <itp> (bug #1069794)
CVE-2026-40250 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1134642)
+ - openexr 3.4.14-0.1 (bug #1134642)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-m5qw-23x2-6phj
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2346
NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/416fecf71241c097d52da5b219d36afd94800e69 (main)
NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/42d394a7b761325a3df7c2d57f9dfd905629ca4f (v3.4.10-rc)
NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/a41f0d19841469148aabf7e1e056fab9f1c3c4f0 (v3.2.8-rc)
CVE-2026-40244 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1134642)
+ - openexr 3.4.14-0.1 (bug #1134642)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-j526-66f6-fxhx
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2346
NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/416fecf71241c097d52da5b219d36afd94800e69 (main)
@@ -104964,7 +104964,7 @@ CVE-2026-39973 (Apktool is a tool for reverse engineering Android APK files. In
CVE-2026-39946 (OpenBao is an open source identity-based secrets management system. Pr ...)
- openbao <itp> (bug #1069794)
CVE-2026-39886 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1134642)
+ - openexr 3.4.14-0.1 (bug #1134642)
[trixie] - openexr <not-affected> (Vulnerable code not present)
[bookworm] - openexr <not-affected> (Vulnerable code not present)
[bullseye] - openexr <not-affected> (Vulnerable code not present)
@@ -112821,14 +112821,14 @@ CVE-2026-34755 (vLLM is an inference and serving engine for large language model
CVE-2026-34753 (vLLM is an inference and serving engine for large language models (LLM ...)
- vllm <itp> (bug #1095237)
CVE-2026-34589 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1133188)
+ - openexr 3.4.14-0.1 (bug #1133188)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p8xc-w3q4-h64x
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2328
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/e464a33cc5bcd9f7dad2364bf76c08a52a5b0fbf (main)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/ea588c8f075f5915e34931861e15b6c2d3b62561 (v3.4.9-rc)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/ca0139287918775e1fddc0ed0033d694bec033ff (v3.2.7-rc)
CVE-2026-34588 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1133188)
+ - openexr 3.4.14-0.1 (bug #1133188)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-588r-cr5c-w6hf
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2329
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/7c31424f9e381f386af83194d0b0e253da4a24d2 (main)
@@ -112843,21 +112843,21 @@ CVE-2026-34444 (Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In
CVE-2026-34402
REJECTED
CVE-2026-34380 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1133188)
+ - openexr 3.4.14-0.1 (bug #1133188)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-q3v8-hw4m-59w5
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2323
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/f5beec2bd8636102e74460a0b624d3e26efc546f (main)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/b2cebfa1c68e76cb2048ac1c1fbf1b50d196ff9d (v3.4.9-rc)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/a5e5a2eba975b57f77e1c6b6d22ecc49553624e2 (v3.2.7-rc)
CVE-2026-34379 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1133188)
+ - openexr 3.4.14-0.1 (bug #1133188)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-w88v-vqhq-5p24
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2324
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/3ad9b29430f9c2599dad113e1efe619a6ec7ba67 (main)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/d32ffe9d3727c0474b63e91556baf61ced3d89e0 (v3.4.9-rc)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/76af7d7508819a477f2cbce808ee975da8053ce3 (v3.2.7-rc)
CVE-2026-34378 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1133188)
+ - openexr 3.4.14-0.1 (bug #1133188)
[trixie] - openexr <not-affected> (Vulnerable code not present)
[bookworm] - openexr <not-affected> (Vulnerable code not present)
[bullseye] - openexr <not-affected> (Vulnerable code not present)
@@ -115041,15 +115041,15 @@ CVE-2026-34560 (CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a prod
CVE-2026-34559 (CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production ...)
NOT-FOR-US: CI4MS
CVE-2026-34545 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1132578)
+ - openexr 3.4.14-0.1 (bug #1132578)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-ghfj-fx47-wg97
NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/3827998f5c041d6a94c6af24bbb363daa669e4b3 (v3.4.7-rc)
CVE-2026-34544 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1132579)
+ - openexr 3.4.14-0.1 (bug #1132579)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-h762-rhv3-h25v
NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/35e7aa35e22c1975606be86e859f31cc1fc598ee (v3.4.8-rc)
CVE-2026-34543 (OpenEXR provides the specification and reference implementation of the ...)
- - openexr <unfixed> (bug #1132580)
+ - openexr 3.4.14-0.1 (bug #1132580)
NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-vc68-257w-m432
NOTE: Fixed by: https://github.com/AcademySoftwareFoundation/openexr/commit/5f6d0aaa9e43802917af7db90f181e88e083d3b8 (v3.4.8-rc)
CVE-2026-34531 (Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication fo ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e527bcc8c8bdc6f8fed4edae413b6f2af49b8eee
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e527bcc8c8bdc6f8fed4edae413b6f2af49b8eee
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/d3711210/attachment.htm>
More information about the debian-security-tracker-commits
mailing list