Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33809

Опубликовано: 25 мар. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

A flaw was found in golang.org/x/image/tiff. A remote attacker could exploit this vulnerability by providing a maliciously crafted Tagged Image File Format (TIFF) file. This could cause the image decoding process to attempt to allocate up to 4 gigabytes (GiB) of memory. The excessive resource consumption or an out-of-memory error would lead to a Denial of Service (DoS) condition.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorFix deferred
OpenShift Service Mesh 2openshift-golang-builder-containerFix deferred
OpenShift Service Mesh 3openshift-golang-builder-containerFix deferred
Red Hat Enterprise Linux 10golangFix deferred
Red Hat Enterprise Linux 8go-toolset:rhel8/golangFix deferred
Red Hat Enterprise Linux 9golangFix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3golangFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-tests-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift-golang-builder-containerFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1285
https://bugzilla.redhat.com/show_bug.cgi?id=2451437golang: golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via maliciously crafted TIFF file

EPSS

Процентиль: 25%
0.00328
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 5.3
nvd
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 5.3
debian
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to ...

CVSS3: 5.3
github
4 месяца назад

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость библиотеки golang.org/x/image/tiff языка программирования Go, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 25%
0.00328
Низкий

6.5 Medium

CVSS3