A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".
CVSS Details
- CVSS 4.0 Base Score: 1.1 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 2.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade tiff | Sep 22, 2025 | Aug 19, 2025 |
| Amazon Linux Ami 2 | — | Upgrade libtiff-develUpgrade libtiff-toolsUpgrade libtiffUpgrade libtiff-debuginfoUpgrade libtiff-static | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade libtiff-debugsourceUpgrade libtiff-debuginfoUpgrade libtiff-develUpgrade libtiff-staticUpgrade libtiffUpgrade libtiff-toolsUpgrade libtiff-tools-debuginfo | Sep 16, 2025 | Aug 19, 2025 |
| Debian | — | Upgrade tiff | Jul 23, 2026 | Jul 23, 2026 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libtiff | Dec 12, 2025 | Nov 11, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade libtiff | Nov 12, 2025 | Nov 11, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade libtiff | Dec 12, 2025 | Nov 11, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Aug 19, 2025 |
| Suse | — | Upgrade libtiff-devel-32bitUpgrade libtiff5Upgrade tiffUpgrade libtiff6Upgrade libtiff-develUpgrade libtiff5-32bitUpgrade libtiff6-32bit | Dec 5, 2025 | Sep 24, 2025 |
| Ubuntu | — | Upgrade libtiff5Upgrade libtiff6Upgrade libtiff5 (Ubuntu Pro) | Sep 30, 2025 | Aug 19, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Aug 19, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub