6.1

CVE-2026-18495

Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat Hardened Images
Default Statusaffected
Version 4.7.2-2.hum1
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ceph Storage 4
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Ceph Storage 6
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Ceph Storage 7
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Ceph Storage 8
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Ceph Storage 9
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 6
Default Statusunknown
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 7
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 7
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusaffected
HerstellerRed Hat
≫
Produkt Red Hat Hardened Images
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.019
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 6.1 1.3 4.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

https://access.redhat.com/errata/RHSA-2026:53467
https://access.redhat.com/security/cve/CVE-2026-18495
https://bugzilla.redhat.com/show_bug.cgi?id=2531414
https://gitlab.com/libtiff/libtiff/-/merge_requests/729
https://gitlab.com/libtiff/libtiff/-/tree/67fd283d276f09db54dc39b9ef7b979d4b45c4b1