A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade compat-libtiff3Upgrade libtiff-toolsUpgrade libtiff-develUpgrade libtiff | Jul 23, 2026 | Jul 21, 2026 |
| Amazon Linux Ami 2 | — | Upgrade compat-libtiff3Upgrade libtiff-toolsUpgrade libtiffUpgrade libtiff-staticUpgrade libtiff-debuginfoUpgrade compat-libtiff3-debuginfoUpgrade libtiff-devel | Jul 22, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade libtiff-toolsUpgrade libtiff-staticUpgrade libtiff-debuginfoUpgrade libtiff-tools-debuginfoUpgrade libtiff-debugsourceUpgrade libtiffUpgrade libtiff-devel | Jul 21, 2026 | Jun 29, 2026 |
| Debian | — | Upgrade tiff | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | Upgrade libtiffUpgrade compat-libtiff3Upgrade libtiff-tools-debuginfoUpgrade libtiff-toolsNo solution existsUpgrade compat-libtiff3-debugsourceUpgrade compat-libtiff3-debuginfoUpgrade libtiff-debuginfoUpgrade libtiff-develUpgrade libtiff-debugsource | Jul 17, 2026 | Apr 16, 2026 |
| Rocky_linux | — | Upgrade compat-libtiff3Upgrade libtiff-toolsUpgrade libtiff-debuginfoUpgrade libtiff-develUpgrade libtiff-debugsourceUpgrade libtiff-tools-debuginfoUpgrade compat-libtiff3-debuginfoUpgrade libtiffUpgrade compat-libtiff3-debugsource | Jul 27, 2026 | Jul 22, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 13, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub