Ubuntu alert USN-8438-1 (openimageio)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8438-1] OpenImageIO vulnerabilities | |
| Date: | Tue, 16 Jun 2026 23:30:42 +0000 | |
| Message-ID: | <E1wZdEw-0004Ak-49@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8438-1 June 16, 2026 openimageio vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in OpenImageIO. Software Description: - openimageio: Library for reading and writing images Details: It was discovered that OpenImageIO incorrectly performed bounds checking when processing SGI files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-43903) It was discovered that OpenImageIO incorrectly handled run-length encoding when processing Softimage PIC files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-43904) It was discovered that OpenImageIO incorrectly validated subimage metadata when processing HEIF files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-43906) It was discovered that OpenImageIO contained multiple integer overflow vulnerabilities when processing DPX files. An attacker could possibly use these issues to cause a denial of service or execute arbitrary code. (CVE-2026-43907, CVE-2026-43908, CVE-2026-43909) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libopenimageio-dev 2.5.19.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro libopenimageio2.5 2.5.19.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro openimageio-tools 2.5.19.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro python3-openimageio 2.5.19.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS libopenimageio-dev 2.4.17.0+dfsg-1.1ubuntu0.1~esm1 Available with Ubuntu Pro libopenimageio2.4t64 2.4.17.0+dfsg-1.1ubuntu0.1~esm1 Available with Ubuntu Pro openimageio-tools 2.4.17.0+dfsg-1.1ubuntu0.1~esm1 Available with Ubuntu Pro python3-openimageio 2.4.17.0+dfsg-1.1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS libopenimageio-dev 2.1.12.0~dfsg0-1ubuntu0.1~esm1 Available with Ubuntu Pro libopenimageio2.1 2.1.12.0~dfsg0-1ubuntu0.1~esm1 Available with Ubuntu Pro openimageio-tools 2.1.12.0~dfsg0-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-openimageio 2.1.12.0~dfsg0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libopenimageio-dev 1.7.17~dfsg0-1ubuntu2+esm1 Available with Ubuntu Pro libopenimageio1.7 1.7.17~dfsg0-1ubuntu2+esm1 Available with Ubuntu Pro openimageio-tools 1.7.17~dfsg0-1ubuntu2+esm1 Available with Ubuntu Pro python-openimageio 1.7.17~dfsg0-1ubuntu2+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libopenimageio-dev 1.6.11~dfsg0-1ubuntu1+esm2 Available with Ubuntu Pro libopenimageio1.6 1.6.11~dfsg0-1ubuntu1+esm2 Available with Ubuntu Pro openimageio-tools 1.6.11~dfsg0-1ubuntu1+esm2 Available with Ubuntu Pro python-openimageio 1.6.11~dfsg0-1ubuntu1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8438-1 CVE-2026-43903, CVE-2026-43904, CVE-2026-43906, CVE-2026-43907, CVE-2026-43908, CVE-2026-43909
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmox3CAACgkQcpJm3tlz hgFEbRAAtWwPOVc4emuxTOnTxmb6GO6QBtvSNO7/6/w+YTP2q5iRNTEekO66hQoI zj3dlTp5nxX5QxEChbNBJd2d+xX3RwOxT8k2tBk9qAy5YBuMEKZMTRC235aN0OsG hidH+4+lqnU+mgCvQzlMyZVmw0fCWll6EreMoD2wMXTrRbTFTIBr/xef1UXLst9M WuPaior9htouR0mjJP/KmZngHdMk2+hlYLB6D9XGrXTnCKcXOremVOPTG8xlCTV5 f2IwDnRyM90PvmFQt11FqYs1CkgIfizQ5xU3p3X6RmovnwzCDjLeWtgQuZA/Iy2Z mznF1NhGYDrcPLnuWEachbJXyBwToiWOIm8kQ7Up2+Xk4DT55KooiZfpYbK+AJAl wcjYc5HxoiSTGft6jt6nBbw64F6d+uB0Zi5RobZDCHl2fFVM2NwYRWsOyfXUsdvF yF37oKMptt4FhZw798J2HQraJAVX3tqDcC/8P/ruV9SjI4Ofh09IrXioQGT4Kr7I U5i0sRTjp4K8oqM0ZcRj75E4G0zHud4BPfIeeAGAvFKcMZlJHOfbGCEp/3kaJB8L U8QztosDtWuSL1rkcMXdZeAOW7KhofeoofKss+Y+siiiVD0xQQf+i7zdhmM4iRyS hqzGvJ3DL9kWlYXD9g+5zImJeXOpmYhKLUank1z94SyoyYRtS78= =os62 -----END PGP SIGNATURE-----
