Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52492

Опубликовано: 24 авг. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

A flaw was found in libtiff. An integer overflow vulnerability exists in the cvtRaster() function of the rgb2ycbcr utility. When processing a specially crafted TIFF image during YCbCr conversion, an attacker could trigger an undersized heap allocation, leading to a heap-based buffer overflow. This could potentially allow for arbitrary code execution.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted or maliciously crafted TIFF images with the rgb2ycbcr utility. Users should exercise caution when handling TIFF files from unknown or suspicious sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libtiffAffected
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Not affected
Red Hat Enterprise Linux 7libtiffAffected
Red Hat Enterprise Linux 8compat-libtiff3Not affected
Red Hat Enterprise Linux 8libtiffNot affected
Red Hat Enterprise Linux 8mingw-libtiffAffected
Red Hat Enterprise Linux 9libtiffNot affected
Red Hat Hardened ImagesboostNot affected
Red Hat Hardened Imageslibtiff-main-4.7.2-2.hum1FixedRHSA-2026:5346711.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2523134libtiff: libtiff: Arbitrary code execution via crafted TIFF image

EPSS

Процентиль: 3%
0.0013
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
14 дней назад

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

CVSS3: 7.8
nvd
14 дней назад

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

msrc
11 дней назад

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

CVSS3: 7.8
debian
14 дней назад

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() fun ...

CVSS3: 7.8
github
14 дней назад

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

EPSS

Процентиль: 3%
0.0013
Низкий

7.3 High

CVSS3