OpenImageIO Vulnerabilities Affect Multiple Ubuntu Releases

OpenImageIO Vulnerabilities Affect Multiple Ubuntu Releases

First seen 17 Jun 2026, 03:29 UTC UbuntuLinuxsecurity 96% similarity 70.5

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were discovered in OpenImageIO, affecting Ubuntu 20.04 LTS, 24.04 LTS, and 26.04 LTS. The flaws include improper bounds checking and metadata validation, allowing potential denial of service or arbitrary code execution. Specific CVEs include CVE-2026-43903, CVE-2026-43904, and CVE-2026-43906, among others. The vulnerabilities were published on May 14, 2026, and are critical for users of the affected Ubuntu versions. Users are advised to update their systems to mitigate these risks. The issues were confirmed by Ubuntu's security notice USN-8438-1.

Key Points: • OpenImageIO vulnerabilities could lead to denial of service or code execution. • Affected Ubuntu versions include 20.04 LTS, 24.04 LTS, and 26.04 LTS. • Patches are available; users are urged to update their systems promptly.

ThreatCluster AI How this analysis works

Timeline

2026-05-14
CVE-2026-43903 published
Bounds checking issue in OpenImageIO allows potential denial of service or code execution.
Ubuntu
2026-05-14
CVE-2026-43904 published
Improper handling of run-length encoding in OpenImageIO could lead to exploitation.
Ubuntu
2026-05-14
CVE-2026-43906 published
Validation failure of subimage metadata in HEIF files poses security risks.
Ubuntu
2026-05-14
CVE-2026-43908 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-14
CVE-2026-43909 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-14
CVE-2026-43907 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-16
Security notice USN-8438-1 released
Ubuntu released a security notice detailing vulnerabilities in OpenImageIO and recommended updates.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story