Executive brief
libtiff is a widely used library for reading and writing Tagged Image File Format (TIFF) files, common in professional imaging and document processing. A security flaw allows a specially crafted image to cause a memory overflow when processed by the library. If an application using libtiff opens such a file, it could lead to a system crash or allow an attacker to gain unauthorized control over the application.
Technical details
A heap-based buffer overflow (CWE-122) exists in libtiff's PixarLog codec, specifically within the `horizontalAccumulate8abgr` function and `PixarLogDecode` in `tif_pixarlog.c`. The flaw is triggered when decoding images with `PIXARLOGDATAFMT_8BITABGR` output format and a stride of 3. In this configuration, the decoder writes 4 bytes per 3 decoded samples (adding a synthetic alpha byte) but incorrectly advances the output cursor by only 3 bytes. This pointer mismatch results in a linear overflow of approximately 'width' bytes per scanline. An attacker can exploit this by providing a crafted TIFF image to an application that utilizes these specific libtiff fields, potentially achieving arbitrary code execution. A fix involving corrected pointer advancement and scanline size overrides has been proposed in the libtiff GitLab repository.
Affected products
- libtiff libtiff 4.7.1
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
Timeline
- 2026-04-23: patched: Merge request 873 created to address the issue
- 2026-06-25: disclosed: Initial report to Red Hat Bugzilla
- 2026-06-29: advisory: CVE published by Red Hat