PT-2026-21536 · Libtiff+2 · Libtiff+2

Published

2025-01-01

·

Updated

2026-04-16

·

CVE-2025-61143

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libtiff versions up to 4.7.1
Description The software component libtiff, specifically through the tif open.c file, contains a flaw that allows for a NULL pointer dereference. This issue could potentially lead to unexpected behavior or denial of service.
Recommendations Update libtiff to a version later than 4.7.1.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-78308
AZL-78327
CVE-2025-61143
ECHO-3392-C943-A0D7
OESA-2026-1441
OESA-2026-1442
RHSA-2026:7504
SUSE-SU-2026:1407-1
SUSE-SU-2026:1408-1
USN-8113-1

Affected Products

Linuxmint
Ubuntu
Libtiff