Buffer Overflow in libtiff Affects Remote Code Execution with PixarLog Images
CVE-2026-12912
7.3HIGH
What is CVE-2026-12912?
A vulnerability has been identified in libtiff that allows a remote attacker to exploit a specially crafted PixarLog-compressed TIFF image. When decoding images with the PIXARLOGDATAFMT_8BITABGR output format, specifically with a certain stride value, this flaw can lead to a heap-based buffer overflow. Exploitation of this vulnerability could allow an attacker to execute arbitrary code or cause a denial of service (DoS), posing a serious risk to systems utilizing affected versions of the product.
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Ariel Schön for reporting this issue.