StackPatch is liveSee product

Back to CVE digest
CVE-2026-43907 · cross-distro fix matrix

CVE-2026-43907: It was discovered that OpenImageIO incorrectly performed bounds

Affects 5 Linux releases across 30 (distro × package) combinations. First disclosed: 2026-05-14.

CVSS v3:HIGH · 8.3(NVD-published)

Fix per ecosystem

Each block below is a distro release where CVE-2026-43907 has a known fix. Run the listed command on that distro to remediate.

Ubuntu bionic

Source: Ubuntu USN

  • openimageio→ fixed in1.7.17~dfsg0-1ubuntu2+esm1USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio
  • libopenimageio-dev→ fixed in1.7.17~dfsg0-1ubuntu2+esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-dev
  • libopenimageio-doc→ fixed in1.7.17~dfsg0-1ubuntu2+esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-doc
  • libopenimageio1.7→ fixed in1.7.17~dfsg0-1ubuntu2+esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio1.7
  • openimageio-tools→ fixed in1.7.17~dfsg0-1ubuntu2+esm1USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio-tools
  • python-openimageio→ fixed in1.7.17~dfsg0-1ubuntu2+esm1USN-8438-1
    sudo apt-get install --only-upgrade -y python-openimageio

Ubuntu focal

Source: Ubuntu USN

  • openimageio→ fixed in2.1.12.0~dfsg0-1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio
  • libopenimageio-dev→ fixed in2.1.12.0~dfsg0-1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-dev
  • libopenimageio-doc→ fixed in2.1.12.0~dfsg0-1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-doc
  • libopenimageio2.1→ fixed in2.1.12.0~dfsg0-1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio2.1
  • openimageio-tools→ fixed in2.1.12.0~dfsg0-1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio-tools
  • python3-openimageio→ fixed in2.1.12.0~dfsg0-1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y python3-openimageio

Ubuntu noble

Source: Ubuntu USN

  • openimageio→ fixed in2.4.17.0+dfsg-1.1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio
  • libopenimageio-dev→ fixed in2.4.17.0+dfsg-1.1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-dev
  • libopenimageio-doc→ fixed in2.4.17.0+dfsg-1.1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-doc
  • libopenimageio2.4t64→ fixed in2.4.17.0+dfsg-1.1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio2.4t64
  • openimageio-tools→ fixed in2.4.17.0+dfsg-1.1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio-tools
  • python3-openimageio→ fixed in2.4.17.0+dfsg-1.1ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y python3-openimageio

Ubuntu resolute

Source: Ubuntu USN

  • openimageio→ fixed in2.5.19.1+dfsg-2ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio
  • libopenimageio-dev→ fixed in2.5.19.1+dfsg-2ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-dev
  • libopenimageio-doc→ fixed in2.5.19.1+dfsg-2ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-doc
  • libopenimageio2.5→ fixed in2.5.19.1+dfsg-2ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio2.5
  • openimageio-tools→ fixed in2.5.19.1+dfsg-2ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio-tools
  • python3-openimageio→ fixed in2.5.19.1+dfsg-2ubuntu0.1~esm1USN-8438-1
    sudo apt-get install --only-upgrade -y python3-openimageio

Ubuntu xenial

Source: Ubuntu USN

  • openimageio→ fixed in1.6.11~dfsg0-1ubuntu1+esm2USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio
  • libopenimageio-dev→ fixed in1.6.11~dfsg0-1ubuntu1+esm2USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-dev
  • libopenimageio-doc→ fixed in1.6.11~dfsg0-1ubuntu1+esm2USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio-doc
  • libopenimageio1.6→ fixed in1.6.11~dfsg0-1ubuntu1+esm2USN-8438-1
    sudo apt-get install --only-upgrade -y libopenimageio1.6
  • openimageio-tools→ fixed in1.6.11~dfsg0-1ubuntu1+esm2USN-8438-1
    sudo apt-get install --only-upgrade -y openimageio-tools
  • python-openimageio→ fixed in1.6.11~dfsg0-1ubuntu1+esm2USN-8438-1
    sudo apt-get install --only-upgrade -y python-openimageio
Are YOU affected by CVE-2026-43907?

5-second check on your actual server. Reads /etc/os-release, uname -r, and the distro's package manager; matches against this same cross-source index live.

curl https://mindsparkstack.com/scan.sh | bash
Continuous monitoring beats manual checking

CVE-2026-43907dropped silently in your distro's update channel. Every new CVE is the same story. StackPatch runs the matcher hourly against all 5 sources and emails the exact remediation when something new applies to one of your servers. From $9/mo, 14-day free trial, cancel anytime.

See StackPatch (from $9/mo)