Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:41892

Опубликовано: 22 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: libtiff security, bug fix, and enhancement update

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

  • libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM (CVE-2023-52355)

  • libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)

Bug Fix(es) and Enhancement(s):

  • Reintroduce the tiffcp -i option (JIRA:Rocky Linux-185328)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
libtiff-develx86_648.el10_2.4libtiff-devel-4.6.0-8.el10_2.4.x86_64.rpm
libtiffx86_648.el10_2.4libtiff-4.6.0-8.el10_2.4.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
11 дней назад

ELSA-2026-41892: libtiff security, bug fix, and enhancement update (IMPORTANT)

CVSS3: 7.5
ubuntu
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
redhat
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
nvd
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

msrc
11 месяцев назад

Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom