PT-2026-27440 · Libtiff+1 · Libtiff+1

Osidb Bzimport

·

Published

2026-01-01

·

Updated

2026-06-10

·

CVE-2026-4775

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libtiff (affected versions not specified)
Description A flaw exists in the libtiff library where a signed integer overflow in the putcontig8bitYCbCr44tile function can be triggered by a specially crafted TIFF file. This can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially resulting in a denial of service (application crash) or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:12265
ALSA-2026:12271
ALSA-2026:14929
ALSA-2026:16055
ALSA-2026:19150
ALSA-2026:19363
ALSA-2026:20585
CVE-2026-4775
ECHO-2CCD-8B25-A651
OPENSUSE-SU-2026:10650-1
RHSA-2026:12265
RHSA-2026:12271
RHSA-2026:14929
RHSA-2026:16055
RHSA-2026:19150
RHSA-2026:19363
RHSA-2026:19585
RHSA-2026:19586
RHSA-2026:19604
RHSA-2026:19608
RHSA-2026:19609
RHSA-2026:19657
RHSA-2026:19659
RHSA-2026:19702
RHSA-2026:20583
RHSA-2026:20585
RHSA-2026:20591
RHSA-2026:20592

Affected Products

Rocky Linux
Libtiff