vulnerability
Red Hat: CVE-2022-2521: Invalid pointer free operation in TIFFClose() at tif_close.c (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:N/I:N/A:C) | Aug 31, 2022 | Jan 13, 2023 | Sep 1, 2025 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
Published
Aug 31, 2022
Added
Jan 13, 2023
Modified
Sep 1, 2025
Description
It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input.
Solutions
no-fix-redhat-rpm-packageredhat-upgrade-libtiffredhat-upgrade-libtiff-debuginforedhat-upgrade-libtiff-debugsourceredhat-upgrade-libtiff-develredhat-upgrade-libtiff-toolsredhat-upgrade-libtiff-tools-debuginfo
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.