<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 13:41:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-03140</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03140</link>
      <description>bdu:2026-03140</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03140</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0281 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0281</link>
      <description>certfr-2026-avi-0281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0281</guid>
    </item>
    <item>
      <title>EUVD-2026-260673</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260673</link>
      <description>EUVD-2026-260673</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260673</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64181</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64181</link>
      <description>&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64181</guid>
    </item>
    <item>
      <title>GHSA-3h9h-qfvw-98hq — OpenEXR Makes Use of Uninitialized Memory</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3h9h-qfvw-98hq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: OpenEXR&lt;/p&gt;
&lt;p&gt;### Summary
While fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory (CWE-457). The issue is reproducible with the current OSS-Fuzz harness and a single-file PoC.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Environment:**
- Tooling: `valgrind --tool=memcheck --track-origins=yes`
- Target: `openexr_exrcheck_fuzzer`
- OS: Ubuntu 20.04.6 LTS focal x86_64
- openexr version and Git-commit hash: ` openexr 3.4.2 | commit fd657e8a41e157e5841c7cc2e2a5efe094b069a1 (grafted, HEAD -&amp;gt; main, origin/main, origin/HEAD)`&lt;/p&gt;
&lt;p&gt;Function: `generic_unpack`&lt;/p&gt;
&lt;p&gt;Possible root cause (based on observed symptoms):
The unpacker is branching on bytes in a scratch buffer that were never written because the decode step didn’t fully populate it.
- The first use flagged is in `generic_unpack()`. That function reads from the decompressed/expanded pixel buffer to scatter data into the framebuffer. A “conditional jump depends on uninitialised value(s)” means it’s consulting bytes in that buffer before they were written.
- Valgrind says the uninitialised value “was created by a heap allocation (malloc)”, not the stack: this matches a per-tile/per-scanline decode scratch buffer allocated in `exr_decoding_run()`.&lt;/p&gt;
&lt;p&gt;**Valgrind Trace (top frames):**
```bash
==454== Conditional jump or move depends on uninitialised value(s)
==454==    at 0x4539BE: generic_unpack (in /out/openexr_exrcheck_fuzzer)
==454==    by 0x44B85F: exr_decod…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: OpenEXR&lt;/p&gt;
&lt;p&gt;### Summary
While fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory (CWE-457). The issue is reproducible with the current OSS-Fuzz harness and a single-file PoC.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Environment:**
- Tooling: `valgrind --tool=memcheck --track-origins=yes`
- Target: `openexr_exrcheck_fuzzer`
- OS: Ubuntu 20.04.6 LTS focal x86_64
- openexr version and Git-commit hash: ` openexr 3.4.2 | commit fd657e8a41e157e5841c7cc2e2a5efe094b069a1 (grafted, HEAD -&amp;gt; main, origin/main, origin/HEAD)`&lt;/p&gt;
&lt;p&gt;Function: `generic_unpack`&lt;/p&gt;
&lt;p&gt;Possible root cause (based on observed symptoms):
The unpacker is branching on bytes in a scratch buffer that were never written because the decode step didn’t fully populate it.
- The first use flagged is in `generic_unpack()`. That function reads from the decompressed/expanded pixel buffer to scatter data into the framebuffer. A “conditional jump depends on uninitialised value(s)” means it’s consulting bytes in that buffer before they were written.
- Valgrind says the uninitialised value “was created by a heap allocation (malloc)”, not the stack: this matches a per-tile/per-scanline decode scratch buffer allocated in `exr_decoding_run()`.&lt;/p&gt;
&lt;p&gt;**Valgrind Trace (top frames):**
```bash
==454== Conditional jump or move depends on uninitialised value(s)
==454==    at 0x4539BE: generic_unpack (in /out/openexr_exrcheck_fuzzer)
==454==    by 0x44B85F: exr_decod…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3h9h-qfvw-98hq</guid>
    </item>
    <item>
      <title>OESA-2025-2710 — OpenEXR security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2710</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: OpenEXR&lt;/p&gt;
&lt;p&gt;OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light &amp;amp;amp;amp; Magic for use in computer imaging applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.(CVE-2025-64181)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: OpenEXR&lt;/p&gt;
&lt;p&gt;OpenEXR is a high dynamic-range (HDR) image file format originally developed by Industrial Light &amp;amp;amp;amp; Magic for use in computer imaging applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.(CVE-2025-64181)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2710</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15741-1 — libIex-3_4-33-3.4.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15741-1</link>
      <description>&lt;p&gt;libIex-3_4-33-3.4.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libIex-3_4-33-3.4.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15741-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2843 — OpenEXR Makes Use of Uninitialized Memory</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2843</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openexr&lt;/p&gt;
&lt;p&gt;### Summary
While fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory (CWE-457). The issue is reproducible with the current OSS-Fuzz harness and a single-file PoC.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Environment:**
- Tooling: `valgrind --tool=memcheck --track-origins=yes`
- Target: `openexr_exrcheck_fuzzer`
- OS: Ubuntu 20.04.6 LTS focal x86_64
- openexr version and Git-commit hash: ` openexr 3.4.2 | commit fd657e8a41e157e5841c7cc2e2a5efe094b069a1 (grafted, HEAD -&amp;gt; main, origin/main, origin/HEAD)`&lt;/p&gt;
&lt;p&gt;Function: `generic_unpack`&lt;/p&gt;
&lt;p&gt;Possible root cause (based on observed symptoms):
The unpacker is branching on bytes in a scratch buffer that were never written because the decode step didn’t fully populate it.
- The first use flagged is in `generic_unpack()`. That function reads from the decompressed/expanded pixel buffer to scatter data into the framebuffer. A “conditional jump depends on uninitialised value(s)” means it’s consulting bytes in that buffer before they were written.
- Valgrind says the uninitialised value “was created by a heap allocation (malloc)”, not the stack: this matches a per-tile/per-scanline decode scratch buffer allocated in `exr_decoding_run()`.&lt;/p&gt;
&lt;p&gt;**Valgrind Trace (top frames):**
```bash
==454== Conditional jump or move depends on uninitialised value(s)
==454==    at 0x4539BE: generic_unpack (in /out/openexr_exrcheck_fuzzer)
==454==    by 0x44B85F: exr_decod…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openexr&lt;/p&gt;
&lt;p&gt;### Summary
While fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory (CWE-457). The issue is reproducible with the current OSS-Fuzz harness and a single-file PoC.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Environment:**
- Tooling: `valgrind --tool=memcheck --track-origins=yes`
- Target: `openexr_exrcheck_fuzzer`
- OS: Ubuntu 20.04.6 LTS focal x86_64
- openexr version and Git-commit hash: ` openexr 3.4.2 | commit fd657e8a41e157e5841c7cc2e2a5efe094b069a1 (grafted, HEAD -&amp;gt; main, origin/main, origin/HEAD)`&lt;/p&gt;
&lt;p&gt;Function: `generic_unpack`&lt;/p&gt;
&lt;p&gt;Possible root cause (based on observed symptoms):
The unpacker is branching on bytes in a scratch buffer that were never written because the decode step didn’t fully populate it.
- The first use flagged is in `generic_unpack()`. That function reads from the decompressed/expanded pixel buffer to scatter data into the framebuffer. A “conditional jump depends on uninitialised value(s)” means it’s consulting bytes in that buffer before they were written.
- Valgrind says the uninitialised value “was created by a heap allocation (malloc)”, not the stack: this matches a per-tile/per-scanline decode scratch buffer allocated in `exr_decoding_run()`.&lt;/p&gt;
&lt;p&gt;**Valgrind Trace (top frames):**
```bash
==454== Conditional jump or move depends on uninitialised value(s)
==454==    at 0x4539BE: generic_unpack (in /out/openexr_exrcheck_fuzzer)
==454==    by 0x44B85F: exr_decod…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2843</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21014-1 — Security update for openexr</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21014-1</link>
      <description>&lt;p&gt;Security update for openexr&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openexr&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21014-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-64181</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64181</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: openexr, Ubuntu:25.10: openexr&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: openexr, Ubuntu:25.10: openexr&lt;/p&gt;
&lt;p&gt;OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64181</guid>
    </item>
  </channel>
</rss>
