Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-46602

Опубликовано: 25 июн. 2026
Источник: debian

Описание

The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-golang-x-imageunfixedpackage
golang-golang-x-imageno-dsatrixiepackage
golang-golang-x-imagepostponedbookwormpackage
golang-golang-x-imagepostponedbullseyepackage

Примечания

  • https://github.com/golang/go/issues/79905

  • Fixed by: https://github.com/golang/image/commit/304d4cc4ee82f96f864f1a4c9a3ae30a4016c9ce (v0.43.0)

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.

CVSS3: 7.5
nvd
около 2 месяцев назад

The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.

CVSS3: 7.5
github
около 2 месяцев назад

The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.