Bug 2454254

Summary: CVE-2026-34545 usd: OpenEXR: Remote code execution via crafted EXR files [fedora-all]
Product: [Fedora] Fedora Reporter: Sandipan Roy <saroy>
Component: usdAssignee: Luya Tshimbalanga <luya_tfz>
Status: CLOSED NOTABUG QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: rawhideCC: adriacabellocrespo, aekoroglu, code, luya_tfz, multimedia-sig, negativo17
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["c2a5070d-0fe0-4376-bb94-9134e657036a"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-04-05 18:25:51 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2454139    

Description Sandipan Roy 2026-04-02 08:29:14 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Ben Beasley 2026-04-05 18:25:51 UTC
According to https://www.cve.org/CVERecord?id=CVE-2026-34545, the vulnerability existed, and was fixed by https://github.com/AcademySoftwareFoundation/openexr/commit/3827998f5c041d6a94c6af24bbb363daa669e4b3, in the ht_undo_impl function. No function of that name is present in the OpenEXR subset that is bundled in OpenUSD, and searching for snippets of context surrounding the changes in the fix doesn’t turn up any evidence that related code, even after refactoring, might be present in OpenUSD. Therefore, I conclude that the usd package appears to be unaffected.