[Git][security-tracker-team/security-tracker][master] new openexr issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Aug 25 20:47:41 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ebe3ba4d by Moritz Muehlenhoff at 2026-08-25T21:46:54+02:00
new openexr issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -265,9 +265,20 @@ CVE-2026-63587 (The SMS control function of IE-SR-2TX-WL-4G devices can require
 CVE-2026-63586 (The web-based management interface uses a modified uhttpd server with  ...)
 	TODO: check
 CVE-2026-62986 (OpenEXR is the reference implementation and specification for the EXR  ...)
-	TODO: check
+	- openexr 3.4.14-0.1
+	[trixie] - openexr <not-affected> (Vulnerable code not present, introduced in 3.3)
+	[bookworm] - openexr <not-affected> (Vulnerable code not present, introduced in 3.3)
+	[bullseye] - openexr <not-affected> (Vulnerable code not present, introduced in 3.3)
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-pf59-r2mc-x746
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/36ff0968de08d7ae80792f9f53402f93433207bb (main)
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/5105809507ba572d8cad12ec9f5a5c9d378354b9 (v3.4.14-rc)
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/5a534e2228c853034e5cb9d2599ebf82f48f51b0 (v3.3.13-rc)
+	NOTE: Introduced by: https://github.com/AcademySoftwareFoundation/openexr/commit/84d7d52e17a17e18d138d9d1aa9f4e2de2fcb2d6 (v3.3.0-rc)
 CVE-2026-61555 (OpenEXR is the reference implementation and specification for the EXR  ...)
-	TODO: check
+	- openexr 3.4.14-0.1
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-g8f2-r72m-48vx
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/6c6bc2d485f1435d3776b3b4a36f1617cf87070b (v3.4.14-rc)
+	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/c6d3796918f8e358c9c329e909fa6b0dd7dc8cb9 (v3.2.11-rc)
 CVE-2026-59985 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	TODO: check
 CVE-2026-59984 (OpenEXR is the reference implementation and specification for the EXR  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe3ba4dedd08f39419d7362ddf110c2a6c51068

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ebe3ba4dedd08f39419d7362ddf110c2a6c51068
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/c6ee4b4d/attachment.htm>


More information about the debian-security-tracker-commits mailing list