Bug 2454254
| Summary: | CVE-2026-34545 usd: OpenEXR: Remote code execution via crafted EXR files [fedora-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Sandipan Roy <saroy> |
| Component: | usd | Assignee: | Luya Tshimbalanga <luya_tfz> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | rawhide | CC: | adriacabellocrespo, aekoroglu, code, luya_tfz, multimedia-sig, negativo17 |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["c2a5070d-0fe0-4376-bb94-9134e657036a"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-04-05 18:25:51 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2454139 | ||
|
Description
Sandipan Roy
2026-04-02 08:29:14 UTC
According to https://www.cve.org/CVERecord?id=CVE-2026-34545, the vulnerability existed, and was fixed by https://github.com/AcademySoftwareFoundation/openexr/commit/3827998f5c041d6a94c6af24bbb363daa669e4b3, in the ht_undo_impl function. No function of that name is present in the OpenEXR subset that is bundled in OpenUSD, and searching for snippets of context surrounding the changes in the fix doesn’t turn up any evidence that related code, even after refactoring, might be present in OpenUSD. Therefore, I conclude that the usd package appears to be unaffected. |