PT-2026-27440 · Libtiff+2 · Libtiff+2

·

CVE-2026-4775

·

Published

2026-01-01

·

Updated

2026-09-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libtiff (affected versions not specified)
Description A flaw exists in the libtiff library where a signed integer overflow in the putcontig8bitYCbCr44tile function can be triggered by a specially crafted TIFF file. This can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially resulting in a denial of service (application crash) or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:12265
ALSA-2026:12271
ALSA-2026:14929
ALSA-2026:16055
ALSA-2026:19150
ALSA-2026:19363
ALSA-2026:20585
AZL-80843
AZL-80919
BDU:2026-10806
CVE-2026-4775
ECHO-2CCD-8B25-A651
OESA-2026-1806
OPENSUSE-SU-2026:10650-1
OPENSUSE-SU-2026:11261-1
OPENSUSE-SU-2026:20995-1
OPENSUSE-SU-2026:21289-1
RHSA-2026:12265
RHSA-2026:12271
RHSA-2026:14929
RHSA-2026:16055
RHSA-2026:19150
RHSA-2026:19363
RHSA-2026:19585
RHSA-2026:19586
RHSA-2026:19604
RHSA-2026:19608
RHSA-2026:19609
RHSA-2026:19657
RHSA-2026:19659
RHSA-2026:19702
RHSA-2026:20583
RHSA-2026:20585
RHSA-2026:20591
RHSA-2026:20592
RHSA-2026:24992
RHSA-2026:25910
RHSA-2026:30349
RHSA-2026:33388
SUSE-SU-2026:22234-1
SUSE-SU-2026:22306-1
SUSE-SU-2026:22590-1
SUSE-SU-2026:22616-1
SUSE-SU-2026:2853-1

Affected Products

Red Os
Rocky Linux
Libtiff