Buffer Overflow in libtiff Affects Remote Code Execution with PixarLog Images
CVE-2026-12912
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 29 June 2026
What is CVE-2026-12912?
A vulnerability has been identified in libtiff that allows a remote attacker to exploit a specially crafted PixarLog-compressed TIFF image. When decoding images with the PIXARLOGDATAFMT_8BITABGR output format, specifically with a certain stride value, this flaw can lead to a heap-based buffer overflow. Exploitation of this vulnerability could allow an attacker to execute arbitrary code or cause a denial of service (DoS), posing a serious risk to systems utilizing affected versions of the product.
Affected Version(s)
Red Hat Enterprise Linux 10 0:4.6.0-8.el10_2.4
Red Hat Enterprise Linux 10.0 Extended Update Support 0:4.6.0-6.el10_0.4
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:3.9.4-12.el7_9.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved