Описание
Important: libtiff security, bug fix, and enhancement update
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.
Security Fix(es):
-
libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM (CVE-2023-52355)
-
libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)
Bug Fix(es) and Enhancement(s):
- Reintroduce the
tiffcp -ioption (JIRA:Rocky Linux-185328)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Затронутые продукты
Rocky Linux 10
Связанные CVE
Исправления
- Red Hat - 2492871
- Red Hat - 2251326
Связанные уязвимости
ELSA-2026-41892: libtiff security, bug fix, and enhancement update (IMPORTANT)
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom