<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:40:04.572258+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-34543</id>
    <title>BELL-CVE-2026-34543</title>
    <updated>2026-10-03T20:40:04.577316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: openexr</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-34543"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278733</id>
    <title>EUVD-2026-278733</title>
    <updated>2026-10-03T20:40:04.577379+00:00</updated>
    <content>EUVD-2026-278733</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34543</id>
    <title>fkie_cve-2026-34543</title>
    <updated>2026-10-03T20:40:04.577411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34543"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vc68-257w-m432</id>
    <title>GHSA-vc68-257w-m432 — OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)</title>
    <updated>2026-10-03T20:40:04.577447+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: openexr</p>
<p>### Summary
The PXR24 decompression function undo_pxr24_impl in OpenEXR (internal_pxr24.c) ignores the actual decompressed size (outSize) returned by exr_uncompress_buffer() and instead reads from the scratch buffer based solely on the expected size (uncompressed_size) derived from the header metadata.</p>
<p>Additionally, exr_uncompress_buffer() (compression.c:202) treats LIBDEFLATE_SHORT_OUTPUT (where the compressed stream decompresses to fewer bytes than expected) as a successful result rather than an error.</p>
<p>When these two issues are combined, an attacker can craft a PXR24 EXR file containing a valid but truncated zlib stream. As a result, the decoder reads uninitialized heap memory and incorporates it into the output pixel data.</p>
<p>### Details
This issue occurs due to the combination of two flaws.</p>
<p>1. compression.c:202–205 — LIBDEFLATE_SHORT_OUTPUT treated as success
```
else if (res == LIBDEFLATE_SHORT_OUTPUT)
{
    /* TODO: is this an error? */
    return EXR_ERR_SUCCESS;
}
```
libdeflate_zlib_decompress_ex() returns LIBDEFLATE_SHORT_OUTPUT when the compressed stream is successfully decompressed but the resulting output size is smaller than the provided output buffer size. In this case, the actual number of decompressed bytes is written to actual_out. However, the function does not treat this condition as an error and instead returns success.</p>
<p>2. internal_pxr24.c:279–287 — outSize return value ignored
```
rstat = exr_uncompress_buffer(
    decode-&gt;context, compressed_data, co…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vc68-257w-m432"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10505-1</id>
    <title>openSUSE-SU-2026:10505-1 — libIex-3_4-33-3.4.9-1.1 on GA media</title>
    <updated>2026-10-03T20:40:04.577500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libIex-3_4-33-3.4.9-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10505-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2850</id>
    <title>PYSEC-2026-2850 — OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)</title>
    <updated>2026-10-03T20:40:04.577521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: openexr</p>
<p>### Summary
The PXR24 decompression function undo_pxr24_impl in OpenEXR (internal_pxr24.c) ignores the actual decompressed size (outSize) returned by exr_uncompress_buffer() and instead reads from the scratch buffer based solely on the expected size (uncompressed_size) derived from the header metadata.</p>
<p>Additionally, exr_uncompress_buffer() (compression.c:202) treats LIBDEFLATE_SHORT_OUTPUT (where the compressed stream decompresses to fewer bytes than expected) as a successful result rather than an error.</p>
<p>When these two issues are combined, an attacker can craft a PXR24 EXR file containing a valid but truncated zlib stream. As a result, the decoder reads uninitialized heap memory and incorporates it into the output pixel data.</p>
<p>### Details
This issue occurs due to the combination of two flaws.</p>
<p>1. compression.c:202–205 — LIBDEFLATE_SHORT_OUTPUT treated as success
```
else if (res == LIBDEFLATE_SHORT_OUTPUT)
{
    /* TODO: is this an error? */
    return EXR_ERR_SUCCESS;
}
```
libdeflate_zlib_decompress_ex() returns LIBDEFLATE_SHORT_OUTPUT when the compressed stream is successfully decompressed but the resulting output size is smaller than the provided output buffer size. In this case, the actual number of decompressed bytes is written to actual_out. However, the function does not treat this condition as an error and instead returns success.</p>
<p>2. internal_pxr24.c:279–287 — outSize return value ignored
```
rstat = exr_uncompress_buffer(
    decode-&gt;context, compressed_data, co…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34543</id>
    <title>Withdrawn: UBUNTU-CVE-2026-34543</title>
    <updated>2026-10-03T20:40:04.577591+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: openexr, Ubuntu:18.04:LTS: openexr, Ubuntu:Pro:20.04:LTS: openexr, Ubuntu:Pro:22.04:LTS: openexr, Ubuntu:24.04:LTS: openexr, Ubuntu:25.10: openexr, Ubuntu:26.04: openexr</p>
<p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34543"/>
  </entry>
</feed>
