<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:49:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12078</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12078</link>
      <description>bdu:2026-12078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12078</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-34544</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-34544</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: openexr&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: openexr&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-34544</guid>
    </item>
    <item>
      <title>EUVD-2026-278851</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278851</link>
      <description>EUVD-2026-278851</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278851</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34544</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34544</link>
      <description>&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34544</guid>
    </item>
    <item>
      <title>GHSA-h762-rhv3-h25v — OpenEXR: integer overflow to OOB write in uncompress_b44_impl()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h762-rhv3-h25v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openexr&lt;/p&gt;
&lt;p&gt;### Summary
The B44/B44A decoder in OpenEXR reconstructs row pointers into a scratch buffer using int. When the channel width (nx) is large enough, the product y * nx overflows int, causing the row pointer to wrap before the start of the scratch buffer. Subsequent memcpy() calls then write decoded pixel blocks to an invalid address, producing an active out-of-bounds write.&lt;/p&gt;
&lt;p&gt;### Root cause 
* Variable declarations (internal_b44.c:535)
```c
int nx, ny;
```
`nx` and `ny` are declared as plain int. They are assigned from `curc-&amp;gt;width` and `curc-&amp;gt;height` which are int32_t.&lt;/p&gt;
&lt;p&gt;* Scratch buffer allocation (internal_b44:543)
```c
nBytes = (uint64_t) (ny) * (uint64_t) (nx) *
               (uint64_t) (curc-&amp;gt;bytes_per_element);
```
The allocation path correctly promotes to uint64_t before multiplying.
The scratch buffer is always large enough to hold the full channel.&lt;/p&gt;
&lt;p&gt;* Row pointer reconstruction (internal_b44:560)
```c
row0 = (uint16_t*) scratch;
row0 += y * nx;          
row1 = row0 + nx;
row2 = row1 + nx;
row3 = row2 + nx;
```
`y` and `nx` are both int. The product `y * nx` is computed in int. If this product exceeds INT_MAX (2,147,483,647), the result is signed integer overflow&lt;/p&gt;
&lt;p&gt;* Out of Band write (internal_b44:592)
```c
memcpy (row0, &amp;amp;s[0], n);
memcpy (row1, &amp;amp;s[4], n);
memcpy (row2, &amp;amp;s[8], n);
memcpy (row3, &amp;amp;s[12], n);
```
These four writes copy decoded B44 pixel blocks into row0–row3, which now point to memory before the scratch buffer. 
The same pattern is present in the encode…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openexr&lt;/p&gt;
&lt;p&gt;### Summary
The B44/B44A decoder in OpenEXR reconstructs row pointers into a scratch buffer using int. When the channel width (nx) is large enough, the product y * nx overflows int, causing the row pointer to wrap before the start of the scratch buffer. Subsequent memcpy() calls then write decoded pixel blocks to an invalid address, producing an active out-of-bounds write.&lt;/p&gt;
&lt;p&gt;### Root cause 
* Variable declarations (internal_b44.c:535)
```c
int nx, ny;
```
`nx` and `ny` are declared as plain int. They are assigned from `curc-&amp;gt;width` and `curc-&amp;gt;height` which are int32_t.&lt;/p&gt;
&lt;p&gt;* Scratch buffer allocation (internal_b44:543)
```c
nBytes = (uint64_t) (ny) * (uint64_t) (nx) *
               (uint64_t) (curc-&amp;gt;bytes_per_element);
```
The allocation path correctly promotes to uint64_t before multiplying.
The scratch buffer is always large enough to hold the full channel.&lt;/p&gt;
&lt;p&gt;* Row pointer reconstruction (internal_b44:560)
```c
row0 = (uint16_t*) scratch;
row0 += y * nx;          
row1 = row0 + nx;
row2 = row1 + nx;
row3 = row2 + nx;
```
`y` and `nx` are both int. The product `y * nx` is computed in int. If this product exceeds INT_MAX (2,147,483,647), the result is signed integer overflow&lt;/p&gt;
&lt;p&gt;* Out of Band write (internal_b44:592)
```c
memcpy (row0, &amp;amp;s[0], n);
memcpy (row1, &amp;amp;s[4], n);
memcpy (row2, &amp;amp;s[8], n);
memcpy (row3, &amp;amp;s[12], n);
```
These four writes copy decoded B44 pixel blocks into row0–row3, which now point to memory before the scratch buffer. 
The same pattern is present in the encode…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h762-rhv3-h25v</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10505-1 — libIex-3_4-33-3.4.9-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10505-1</link>
      <description>&lt;p&gt;libIex-3_4-33-3.4.9-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libIex-3_4-33-3.4.9-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10505-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2847 — OpenEXR: integer overflow to OOB write in uncompress_b44_impl()</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2847</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openexr&lt;/p&gt;
&lt;p&gt;### Summary
The B44/B44A decoder in OpenEXR reconstructs row pointers into a scratch buffer using int. When the channel width (nx) is large enough, the product y * nx overflows int, causing the row pointer to wrap before the start of the scratch buffer. Subsequent memcpy() calls then write decoded pixel blocks to an invalid address, producing an active out-of-bounds write.&lt;/p&gt;
&lt;p&gt;### Root cause 
* Variable declarations (internal_b44.c:535)
```c
int nx, ny;
```
`nx` and `ny` are declared as plain int. They are assigned from `curc-&amp;gt;width` and `curc-&amp;gt;height` which are int32_t.&lt;/p&gt;
&lt;p&gt;* Scratch buffer allocation (internal_b44:543)
```c
nBytes = (uint64_t) (ny) * (uint64_t) (nx) *
               (uint64_t) (curc-&amp;gt;bytes_per_element);
```
The allocation path correctly promotes to uint64_t before multiplying.
The scratch buffer is always large enough to hold the full channel.&lt;/p&gt;
&lt;p&gt;* Row pointer reconstruction (internal_b44:560)
```c
row0 = (uint16_t*) scratch;
row0 += y * nx;          
row1 = row0 + nx;
row2 = row1 + nx;
row3 = row2 + nx;
```
`y` and `nx` are both int. The product `y * nx` is computed in int. If this product exceeds INT_MAX (2,147,483,647), the result is signed integer overflow&lt;/p&gt;
&lt;p&gt;* Out of Band write (internal_b44:592)
```c
memcpy (row0, &amp;amp;s[0], n);
memcpy (row1, &amp;amp;s[4], n);
memcpy (row2, &amp;amp;s[8], n);
memcpy (row3, &amp;amp;s[12], n);
```
These four writes copy decoded B44 pixel blocks into row0–row3, which now point to memory before the scratch buffer. 
The same pattern is present in the encode…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openexr&lt;/p&gt;
&lt;p&gt;### Summary
The B44/B44A decoder in OpenEXR reconstructs row pointers into a scratch buffer using int. When the channel width (nx) is large enough, the product y * nx overflows int, causing the row pointer to wrap before the start of the scratch buffer. Subsequent memcpy() calls then write decoded pixel blocks to an invalid address, producing an active out-of-bounds write.&lt;/p&gt;
&lt;p&gt;### Root cause 
* Variable declarations (internal_b44.c:535)
```c
int nx, ny;
```
`nx` and `ny` are declared as plain int. They are assigned from `curc-&amp;gt;width` and `curc-&amp;gt;height` which are int32_t.&lt;/p&gt;
&lt;p&gt;* Scratch buffer allocation (internal_b44:543)
```c
nBytes = (uint64_t) (ny) * (uint64_t) (nx) *
               (uint64_t) (curc-&amp;gt;bytes_per_element);
```
The allocation path correctly promotes to uint64_t before multiplying.
The scratch buffer is always large enough to hold the full channel.&lt;/p&gt;
&lt;p&gt;* Row pointer reconstruction (internal_b44:560)
```c
row0 = (uint16_t*) scratch;
row0 += y * nx;          
row1 = row0 + nx;
row2 = row1 + nx;
row3 = row2 + nx;
```
`y` and `nx` are both int. The product `y * nx` is computed in int. If this product exceeds INT_MAX (2,147,483,647), the result is signed integer overflow&lt;/p&gt;
&lt;p&gt;* Out of Band write (internal_b44:592)
```c
memcpy (row0, &amp;amp;s[0], n);
memcpy (row1, &amp;amp;s[4], n);
memcpy (row2, &amp;amp;s[8], n);
memcpy (row3, &amp;amp;s[12], n);
```
These four writes copy decoded B44 pixel blocks into row0–row3, which now point to memory before the scratch buffer. 
The same pattern is present in the encode…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2847</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2026-34544</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34544</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: openexr, Ubuntu:18.04:LTS: openexr, Ubuntu:Pro:20.04:LTS: openexr, Ubuntu:Pro:22.04:LTS: openexr, Ubuntu:24.04:LTS: openexr, Ubuntu:25.10: openexr, Ubuntu:26.04: openexr&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: openexr, Ubuntu:18.04:LTS: openexr, Ubuntu:Pro:20.04:LTS: openexr, Ubuntu:Pro:22.04:LTS: openexr, Ubuntu:24.04:LTS: openexr, Ubuntu:25.10: openexr, Ubuntu:26.04: openexr&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34544</guid>
    </item>
  </channel>
</rss>
