Skip to content
Critical Denial of Service Vulnerabilities in Fedora's MinGW OpenEXR Library

Critical Denial of Service Vulnerabilities in Fedora's MinGW OpenEXR Library

First seen 17 Mar 2026, 06:36 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 18, 2026 at 04:57 UTC

Fedora has released updates for the MinGW Windows OpenEXR library due to significant vulnerabilities. Two critical CVEs have been identified: CVE-2026-26981, published on 2026-02-24, which allows for denial of service via a heap-buffer overflow when parsing malformed EXR files, and CVE-2026-27622, published on 2026-03-03, which enables arbitrary code execution through integer overflow in EXR file processing. The updates are available for versions 3.3.8 and 3.4.6. Users are advised to upgrade their systems using the 'dnf' update program to mitigate these risks. The vulnerabilities affect all Fedora systems utilizing the MinGW OpenEXR library. The potential impact includes service disruptions and unauthorized code execution. Current status indicates that patches are available, but users must act promptly to secure their systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 206d ago How this analysis works

Timeline

2026-02-24
CVE-2026-26981 published
2026-03-03
CVE-2026-27622 published
2026-03-08
Updates released for OpenEXR library
2026-03-17
Articles published detailing vulnerabilities

More articles in this cluster (2)

Following this threat?

Track CVE-2026-26981 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed