[CLSA-2026:1776950756] openexr: Fix of CVE-2026-34588
Type:
security
Severity:
Important
Release date:
2026-04-23 13:26:01 UTC
Description:
- CVE-2026-34588 fix signed 32-bit integer overflow in PIZ decoder wavelet buffer arithmetic leading to out-of-bounds read/write
Updated packages:
  • openexr-3.1.1-3.el9.tuxcare.els4.x86_64.rpm
    sha:be79096253dad8e21c3c6473c63ad41bbb290d53c1bb36d383bc3bae1e872635
  • openexr-devel-3.1.1-3.el9.tuxcare.els4.i686.rpm
    sha:f0ec18c51b86545ef4a391ccf29e78c237e0a79539236ee526907bf0e2793385
  • openexr-devel-3.1.1-3.el9.tuxcare.els4.x86_64.rpm
    sha:a7d8b926d171f77b34995b2d54840eee6f1eb5fe27ad276f52e9d54a03e13021
  • openexr-libs-3.1.1-3.el9.tuxcare.els4.i686.rpm
    sha:a6e46eacdfb8ed23afe7fcc5baaa27ccdba351c36d10f96c1baff1c0493185da
  • openexr-libs-3.1.1-3.el9.tuxcare.els4.x86_64.rpm
    sha:3981603b84ecb7ee2efbccb93c43e81246cb9a5c82361813959cd0ad3e043039
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.