Libtiff · Libtiff · CVE-2026-12912
**Name of the Vulnerable Software and Affected Versions**
libtiff (affected versions not specified)
**Description**
A heap-based buffer overflow exists in the PixarLog decoder. A remote attacker can trigger this issue by providing a specially crafted PixarLog-compressed TIFF image. The flaw occurs during the decoding of images using the `PIXARLOGDATAFMT 8BITABGR` output format combined with a specific stride value. This may lead to arbitrary code execution or a denial of service (DoS).
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.