An update for libtiff is now available for Red Hat Enterprise Linux 10.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.
Security Fix(es):
* libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM
(CVE-2023-52355)
* libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed
TIFF image (CVE-2026-12912)
Bug Fix(es) and Enhancement(s):
* Reintroduce the `tiffcp -i` option (JIRA:RHEL-185328)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2023-52355: Out-of-bounds Write (CWE-787)
CVE-2026-12912: Heap-based Buffer Overflow (CWE-122)
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Zwei Probleme in openssh (Fedora) | 0 | 5 | 19-07-2026 |
| 2 | Zwei Probleme in python-orjson (Fedora) | 0 | 5 | 19-07-2026 |
| 3 | Mehrere Probleme in libseccomp (Fedora) | 0 | 5 | 20-07-2026 |
| 4 | Zwei Probleme in python-asyncssh (Fedora) | 0 | 5 | 20-07-2026 |
| 5 | Zwei Probleme in python-asyncssh (Fedora) | 0 | 5 | 20-07-2026 |
| 6 | Mehrere Probleme in Linux (Ubuntu) | 0 | 5 | 20-07-2026 |
| 7 | Mehrere Probleme in Linux (Ubuntu) | 0 | 5 | 20-07-2026 |
| 8 | Mehrere Probleme in Linux (Ubuntu) | 0 | 5 | 20-07-2026 |
| 9 | Mehrere Probleme in roundcube (Debian) | 0 | 5 | 20-07-2026 |
| 10 | Denial of Service in dovecot (Red Hat) | 0 | 5 | 20-07-2026 |