Integer Overflow to Buffer Overflow in libvips - CVE-2026-70651
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer overflow to buffer overflow in dimension handling in the ImageMagick-based TIFF reader when processing a crafted multi-page TIFF image. A local user can supply a specially crafted multi-page TIFF image to cause a denial of service.
Only libvips builds compiled without libtiff support and with ImageMagick support are vulnerable.