PT-2026-53316 · Libtiff+1 · Libtiff+1

·

CVE-2026-12912

·

Published

2026-04-16

·

Updated

2026-09-02

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libtiff (affected versions not specified)
Description A heap-based buffer overflow exists in the PixarLog decoder. A remote attacker can trigger this issue by providing a specially crafted PixarLog-compressed TIFF image. The flaw occurs during the decoding of images using the PIXARLOGDATAFMT 8BITABGR output format combined with a specific stride value. This may lead to arbitrary code execution or a denial of service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:41892
ALSA-2026:42668
ALSA-2026:47183
ALSA-2026:47184
AZL-91685
AZL-91688
AZL-91722
CVE-2026-12912
ECHO-E768-001A-16BA
OESA-2026-2924
OESA-2026-2925
OESA-2026-2926
OESA-2026-2927
OESA-2026-2981
OPENSUSE-SU-2026:11225-1
OPENSUSE-SU-2026:21289-1
RHSA-2026:34890
RHSA-2026:42668
RHSA-2026:47183
RHSA-2026:47184
RHSA-2026:50774
RHSA-2026:54638
RHSA-2026:54640
RHSA-2026:54642
RHSA-2026:58545
RHSA-2026:58553
RHSA-2026:58554
RHSA-2026:58556
RHSA-2026:61657
SUSE-SU-2026:22590-1
SUSE-SU-2026:22616-1
SUSE-SU-2026:22796-1
SUSE-SU-2026:22886-1
SUSE-SU-2026:2853-1
SUSE-SU-2026:3027-1
SUSE-SU-2026:3054-1

Affected Products

Rocky Linux
Libtiff