Описание
Security update for tiff
This update for tiff fixes the following issues:
Update to version 4.7.2.
Security issues fixed:
- CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779).
- CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434).
Other updates and bugfixes:
- Version 4.7.2:
- Software configuration changes:
- cmake: Fix bundle identifiers to use reverse-DNS format
- cmake: Fix and improve Apple framework build support
- cmake: Use TurboJPEG CONFIG by default (issue #767)
- cmake: changes related to 8-/12-bit modes
- cmake: Replace CMath::CMath with direct link to avoid export.
- Support for iOS-derived builds
- Simplify cmake byte order version check
- Add additional warnings, primarily floating precision conversions and integer arithmetic conversions
- configure.ac: Require bootstrap with at least Autoconf 2.71.
- Library changes:
- New/improved functionalities::
- Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781)
- Bug fixes:
- Handle negative TIFFReadFile results before state updates (issue #854)
- tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip
- tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777)
- tif_dirwrite.c: add integer overflow checks to allocation size calculations
- tif_print.c: add integer overflow checks to allocation size calculations
- tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop
- DumpModeSeek: add bounds check to prevent OOB pointer advance
- TIFFGrowStrips: fix use-after-free on partial realloc failure.
- Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it.
- TIFFRGBAImage: avoid int overflows in put functions (issue #830)
- tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792)
- tif_getimage: Widen pointer-offset arithmetic in tif_getimage
- putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798)
- putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753)
- TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787)
- TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831)
- TIFFLinkDirectory() checks for IFD loops (issue #788)
- Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails.
- TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805)
- TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465)
- tif_getimage: reject tile widths that would overflow toskew (issue #808)
- Fix integer overflow in _TIFFPartialReadStripArray on 32-bit.
- TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777).
- _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917)
- TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode
- _TIFFMergeFields(): avoid NULL ptr dereference (issue #755).
- Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749)
- JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892)
- JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826)
- JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773)
- JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501)
- tif_jpeg: reject mismatched JPEG data precision to avoid write overflow
- Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850)
- PixarLog: error out on invalid ABGR output buffer sizes.
- PixarLog: complete ABGR bounds check for multi-row strip decoding.
- PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824)
- PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789).
- PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797)
- TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072)
- OJPEG: fix integer overflow in subsampling buffer allocation.
- OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795).
- OJPEG fix potential integer overflow/out-of-bounds access (issue #796).
- ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b)
- fix null pointer deference in issue #782.
- fix stack-overflow in issue #784.
- Other changes:
- Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739).
- Harden integer size and offset calculations (issue #897)
- TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication
- Move widening casts inside multiplication scope.
- Lots of compiler warning fixes related to enabling more warning flags
- Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773)
- TIFFFillStrip(): prevent harmless unsigned integer overflow
- Software configuration changes:
Список пакетов
Container suse/kiosk/firefox-esr:latest
Container suse/kiosk/xorg:latest
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Package Hub 15 SP7
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
Ссылки
- Link for SUSE-SU-2026:2853-1
- E-Mail link for SUSE-SU-2026:2853-1
- SUSE Security Ratings
- SUSE Bug 1268434
- SUSE Bug 1269779
- SUSE CVE CVE-2026-12912 page
- SUSE CVE CVE-2026-36849 page
- SUSE CVE CVE-2026-4775 page
Описание
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
Затронутые продукты
Ссылки
- CVE-2026-12912
- SUSE Bug 1269779
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-36849
- SUSE Bug 1268434
Описание
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution.
Затронутые продукты
Ссылки
- CVE-2026-4775
- SUSE Bug 1260411