Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Ubuntu: (Multiple Advisories) (CVE-2025-9900): LibTIFF vulnerabilities

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Sep 23, 2025
Added
Sep 30, 2025
Modified
May 31, 2026

Description

A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted TIFF image file.

By providing an abnormally large image height value in the file's metadata, an attacker can trick the library into writing attacker-controlled color data to an arbitrary memory location. This memory corruption can be exploited to cause a denial of service (application crash) or to achieve arbitrary code execution with the permissions of the user.

Solutions

ubuntu-pro-upgrade-gdal-binubuntu-pro-upgrade-libgdal-devubuntu-pro-upgrade-libgdal-javaubuntu-pro-upgrade-libgdal-perlubuntu-pro-upgrade-libgdal1hubuntu-pro-upgrade-libgdal1iubuntu-pro-upgrade-libqt5pdf5ubuntu-pro-upgrade-libqt5pdfwidgets5ubuntu-pro-upgrade-libqt5webengine-dataubuntu-pro-upgrade-libqt5webengine5ubuntu-pro-upgrade-libqt5webenginecore5ubuntu-pro-upgrade-libqt5webenginewidgets5ubuntu-pro-upgrade-libtiff5ubuntu-pro-upgrade-python-gdalubuntu-pro-upgrade-python3-gdalubuntu-pro-upgrade-qml-module-qtquick-pdfubuntu-pro-upgrade-qml-module-qtwebengineubuntu-pro-upgrade-qt5-image-formats-plugin-pdfubuntu-pro-upgrade-qtpdf5-devubuntu-pro-upgrade-qtwebengine5-devubuntu-pro-upgrade-qtwebengine5-dev-toolsubuntu-pro-upgrade-qtwebengine5-private-devubuntu-pro-upgrade-texmakerubuntu-pro-upgrade-texmaker-dataubuntu-upgrade-libtiff5ubuntu-upgrade-libtiff6

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.