Impact
A numeric truncation error in libtiff's tiff2pdf utility causes a 64‑bit StripByteCounts value to be truncated to a 32‑bit integer. The resulting undersized memory allocation leads to an out‑of‑bounds copy that corrupts heap memory and crashes the process, exposing a classic heap‑buffer overflow (CWE‑122).
Affected Systems
The vulnerability affects a range of Red Hat 4 through 9, the Hummingbird 1 component, Red Hat Enterprise Linux releases 6 through 10, and Red Hat Hardened Images. Red Hat has issued advisory RHSA‑2026:53467 for the affected packages.
Risk and Exploitability
The CVSS base score of 6.1 indicates moderate severity, while an EPSS score of less than 1 % suggests a low likelihood of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. An attacker can trigger the vulnerability by feeding a crafted BigTIFF file to tiff2pdf; if the utility is exposed to untrusted input via a web API, file upload, or other network service, remote exploitation could be possible. The attack is most likely to succeed with local or privileged access to supply the malicious file, though any lack of input validation allows the vulnerable routine to execute with the crafted data, resulting in memory corruption.
OpenCVE Enrichment