Re: git: 2dc02c78e293 - main - security/vuxml: Document security/openexr < 3.4.14 multiple vulnerabilities

Yusuf Yaman <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.ports
Message-ID <[email protected]>
Oops, "security/openexr" in the title is obviously wrong, it should be 
"graphics/openexr".

On 8/14/26 13:08, Yusuf Yaman wrote:
> The branch main has been updated by nxjoseph:
>
> URL: https://cgit.FreeBSD.org/ports/commit/?id=2dc02c78e293e5330d7460047666bc7bfd370e1c
>
> commit 2dc02c78e293e5330d7460047666bc7bfd370e1c
> Author:     Yusuf Yaman <[email protected]>
> AuthorDate: 2026-08-14 10:06:02 +0000
> Commit:     Yusuf Yaman <[email protected]>
> CommitDate: 2026-08-14 10:07:56 +0000
>
>      security/vuxml: Document security/openexr < 3.4.14 multiple vulnerabilities
>      
>      PR:             297486
>      Reported by:    mandree
>      Approved by:    osa, vvd (Mentors, implicit)
> ---
>   security/vuxml/vuln/2026.xml | 57 ++++++++++++++++++++++++++++++++++++++++++++
>   1 file changed, 57 insertions(+)
>
> diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
> index 644e7adea93a..468e15d792f1 100644
> --- a/security/vuxml/vuln/2026.xml
> +++ b/security/vuxml/vuln/2026.xml
> @@ -1,3 +1,60 @@
> +  <vuln vid="56449320-97c5-11f1-84d7-3c7c3fba4204">
> +    <topic>OpenEXR -- 3.4.14 fixes multiple vulnerabilities</topic>
> +    <affects>
> +      <package>
> +	<name>openexr</name>
> +	<range><lt>3.4.14</lt></range>
> +      </package>
> +    </affects>
> +    <description>
> +	<body xmlns="http://www.w3.org/1999/xhtml">
> +	<p>Cary Phillips reports:</p>
> +	<blockquote cite="https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.14">
> +	  <p>[The OpenEXR 3.4.14] release addresses the following security vulnerabilities:</p>
> +	  <ul>
> +	    <li>CVE-2026-68514: PyOpenEXR deep prefixed literal RGB key collision heap buffer overflow</li>
> +	    <li>CVE-2026-68513: PyOpenEXR prefixed literal RGB key collision heap buffer overflow</li>
> +	    <li>CVE-2026-62986: PyOpenEXR deep prefixed RGB stale lane disclosure</li>
> +	    <li>CVE-2026-61703: PyOpenEXR deep mixed RGB heap buffer overflow</li>
> +	    <li>CVE-2026-61555: empty multiView viewFromChannelName file crash</li>
> +	    <li>CVE-2026-59985: ILP32 OpenEXRCore RLE decode heap OOB read DoS</li>
> +	    <li>CVE-2026-59984: ILP32 B44 InputFile decode scratch buffer overflow</li>
> +	    <li>CVE-2026-59983: ILP32 DeepTiledInputFile sample count table decode OOB read</li>
> +	    <li>CVE-2026-59982: ILP32 DWAA InputFile packed AC buffer overflow</li>
> +	    <li>CVE-2026-59981: OpenEXRUtil SampleCountChannel row nonzero dataWindow heap OOB read</li>
> +	    <li>CVE-2026-59189: OpenEXRUtil DeepImageChannel row nonzero dataWindow heap OOB read</li>
> +	    <li>CVE-2026-59187: OpenEXR exrmetrics deep pixelmode heap buffer overflow</li>
> +	    <li>CVE-2026-59186: OpenEXR ILP32 TiledRgbaInputFile large tile Array2D heap OOB write</li>
> +	    <li>CVE-2026-59184: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write</li>
> +	    <li>CVE-2026-59183: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in Deep Tile Decoding</li>
> +	  </ul>
> +	</blockquote>
> +	</body>
> +    </description>
> +    <references>
> +      <cvename>CVE-2026-68514</cvename>
> +      <cvename>CVE-2026-68513</cvename>
> +      <cvename>CVE-2026-62986</cvename>
> +      <cvename>CVE-2026-61703</cvename>
> +      <cvename>CVE-2026-61555</cvename>
> +      <cvename>CVE-2026-59985</cvename>
> +      <cvename>CVE-2026-59984</cvename>
> +      <cvename>CVE-2026-59983</cvename>
> +      <cvename>CVE-2026-59982</cvename>
> +      <cvename>CVE-2026-59981</cvename>
> +      <cvename>CVE-2026-59189</cvename>
> +      <cvename>CVE-2026-59187</cvename>
> +      <cvename>CVE-2026-59186</cvename>
> +      <cvename>CVE-2026-59184</cvename>
> +      <cvename>CVE-2026-59183</cvename>
> +      <url>https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.14</url>
> +    </references>
> +    <dates>
> +      <discovery>2026-08-07</discovery>
> +      <entry>2026-08-14</entry>
> +    </dates>
> +  </vuln>
> +
>     <vuln vid="2c73b6d5-971c-11f1-bdc8-2cf05da270f3">
>       <topic>Gitlab -- vulnerabilities</topic>
>       <affects>
>
-- 
Yusuf Yaman
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.