Integer overflow in LibTIFF - CVE-2026-4775

 

Integer overflow in LibTIFF - CVE-2026-4775

Published: May 26, 2026


Vulnerability identifier: #VU132310
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-4775
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to signed integer overflow leading to an out-of-bounds write in putcontig8bitYCbCr44tile reachable from TIFFReadRGBAImageOriented when parsing a crafted TIFF image using PHOTOMETRIC_YCBCR with 4,4 subsampling. A remote attacker can supply a specially crafted TIFF file to cause a denial of service.

Exploitation requires the application to process the image through the default bottom-left RGBA orientation flow, and successful triggering depends on attacker-controlled image width and sufficient memory allocation.


Affected software

LibTIFF
Debian Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
openEuler
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
compat-libtiff3 (Red Hat package)
compat-libtiff3
libtiff (Red Hat package)
mingw32-libtiff
mingw32-libtiff-static
mingw64-libtiff
mingw64-libtiff-static
mingw-libtiff (Red Hat package)
libtiff
libtiff-doc
libtiff-tools
libtiff-static
libtiff-devel
tiff (Debian package)
libtiff-help
libtiff-debugsource
libtiff-debuginfo

How to mitigate CVE-2026-4775

Install security update from vendor's repository.

compat-libtiff3 (Red Hat package) - addressed in versions 3.9.4-12.el7_9.2, 3.9.4-13.el8_4.2, 3.9.4-13.el8_6.2, 3.9.4-13.el8_8.2, 3.9.4-15.el8_10
compat-libtiff3 - update to 3.9.4-15.0.1
libtiff (Red Hat package) - addressed in versions 4.0.3-35.el7_9.2, 4.0.9-18.el8_4.2, 4.0.9-29.el8_8.2, 4.0.9-37.el8_10, 4.2.0-3.el9_0.3, 4.4.0-8.el9_2.5, 4.4.0-12.el9_4.5, 4.4.0-13.el9_6.4, 4.4.0-15.el9_7.3, 4.6.0-6.el10_1.3
mingw32-libtiff - update to 4.0.9-4
mingw32-libtiff-static - update to 4.0.9-4
mingw64-libtiff - update to 4.0.9-4
mingw64-libtiff-static - update to 4.0.9-4
mingw-libtiff (Red Hat package) - update to 4.0.9-4.el8_10
libtiff - addressed in versions 4.4.0-15.0.1, 4.4.0-18.0.1, 4.7.1-2
libtiff-doc - addressed in versions 4.4.0-15.0.1, 4.4.0-18.0.1, 4.7.1-2
libtiff-tools - addressed in versions 4.4.0-15.0.1, 4.4.0-18.0.1, 4.7.1-2
libtiff-static - addressed in versions 4.4.0-15.0.1, 4.4.0-18.0.1
libtiff-devel - addressed in versions 4.4.0-15.0.1, 4.4.0-18.0.1, 4.7.1-2
tiff (Debian package) - addressed in versions 4.5.0-6+deb12u4, 4.7.0-3+deb13u2
libtiff-help - update to 4.6.0-7
libtiff-tools - update to 4.6.0-7
libtiff-static - update to 4.6.0-7
libtiff-devel - update to 4.6.0-7
libtiff-debugsource - update to 4.6.0-7
libtiff-debuginfo - update to 4.6.0-7
libtiff - update to 4.6.0-7

External References

Related Security Bulletins