PT-2022-6888 · Libtiff+8 · Libtiff+8

Published

2022-05-22

·

Updated

2025-06-03

·

CVE-2022-2521

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libtiff version 4.4.0rc1
Description The issue is related to an invalid pointer free operation in the TIFFClose() function at tif close.c:131, called by tiffcrop.c:2522. This can cause a program crash and denial of service when processing crafted input. The vulnerability is associated with incorrect handling of hard links, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For libtiff version 4.4.0rc1, consider disabling the TIFFClose() function as a temporary workaround until a patch is available. Restrict access to the tiffcrop module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Weakness Enumeration

Related Identifiers

ALSA-2023:0095
ALSA-2023:0302
ALT-PU-2022-3360
ALT-PU-2022-3428
ALT-PU-2025-7532
BDU:2023-05411
CESA-2023_0095
CVE-2022-2521
DSA-5333-1
MGASA-2022-0410
OESA-2022-1917
OPENSUSE-SU-2022_3690-1
OPENSUSE-SU-2024:12420-1
RHSA-2023:0095
RHSA-2023:0302
RHSA-2023_0095
RHSA-2023_0302
RLSA-2023:0095
RLSA-2023:0302
SUSE-SU-2022:3679-1
SUSE-SU-2022:3690-1
USN-5714-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Libtiff