[Git][security-tracker-team/security-tracker][master] Add new openexr issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 15:29:49 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1e99b695 by Salvatore Bonaccorso at 2026-08-25T16:29:17+02:00
Add new openexr issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -188,7 +188,11 @@ CVE-2026-61419 (Dell ThinOS 10, versions prior to 2605_10.2518, contain an Impro
 CVE-2026-5006 (A vulnerability was identified in HashiCorp Vault and Vault Enterprise ...)
 	NOT-FOR-US: HashiCorp
 CVE-2026-59183 (OpenEXR is the reference implementation and specification for the EXR  ...)
-	TODO: check
+	- openexr 3.4.14-0.1
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-rqp5-pmwm-wj6x
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/5e55a64ad1f119a8166542f4b6e034c31b7e043a (v3.4.14-rc)
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/a6cf183725b5665ac3fdbec640125fba5ee1ab39 (v3.3.13-rc)
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/e2adb5be3bbc3a1f82f2bc06cc9699995a99a607 (v3.2.11-rc)
 CVE-2026-56710 (Grav Login plugin versions before 1.0.16 fail to validate the target a ...)
 	NOT-FOR-US: Grav plugin
 CVE-2026-56709 (Grav before 3.9.2 fails to validate untrusted Host headers in the send ...)
@@ -215,15 +219,20 @@ CVE-2026-56702 (Adminer versions before 5.4.3 contain an unrestricted file uploa
 CVE-2026-55468 (Wagtail is an open source content management system built on Django. P ...)
 	NOT-FOR-US: Wagtail
 CVE-2026-55373 (OpenEXR is the reference implementation and specification for the EXR  ...)
-	TODO: check
+	- openexr 3.4.14-0.1
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-mff9-68x3-h8rh
 CVE-2026-55371 (OpenEXR is the reference implementation and specification for the EXR  ...)
-	TODO: check
+	- openexr 3.4.14-0.1
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-xx72-f24p-cf6r
 CVE-2026-55059 (OpenEXR is the reference implementation and specification for the EXR  ...)
-	TODO: check
+	- openexr 3.4.14-0.1
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-54cp-3rq6-7mq8
 CVE-2026-54920 (OpenEXR is the reference implementation and specification for the EXR  ...)
-	TODO: check
+	- openexr 3.4.14-0.1
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-fp75-87pr-8329
 CVE-2026-53532 (OpenEXR is the reference implementation and specification for the EXR  ...)
-	TODO: check
+	- openexr 3.4.14-0.1
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-2f85-52wj-hc3c
 CVE-2026-52492 (An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() fun ...)
 	TODO: check
 CVE-2026-52490 (An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e99b695f103eb9a14c045c17e19a1b0a1e7cbe5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e99b695f103eb9a14c045c17e19a1b0a1e7cbe5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/e83f27c9/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list