Description
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Heap buffer overflow leading to memory corruption
Action: Apply Patch
AI Analysis

Impact

A numeric truncation error in libtiff's tiff2pdf utility causes a 64‑bit StripByteCounts value to be truncated to a 32‑bit integer. The resulting undersized memory allocation leads to an out‑of‑bounds copy that corrupts heap memory and crashes the process, exposing a classic heap‑buffer overflow (CWE‑122).

Affected Systems

The vulnerability affects a range of Red Hat 4 through 9, the Hummingbird 1 component, Red Hat Enterprise Linux releases 6 through 10, and Red Hat Hardened Images. Red Hat has issued advisory RHSA‑2026:53467 for the affected packages.

Risk and Exploitability

The CVSS base score of 6.1 indicates moderate severity, while an EPSS score of less than 1 % suggests a low likelihood of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. An attacker can trigger the vulnerability by feeding a crafted BigTIFF file to tiff2pdf; if the utility is exposed to untrusted input via a web API, file upload, or other network service, remote exploitation could be possible. The attack is most likely to succeed with local or privileged access to supply the malicious file, though any lack of input validation allows the vulnerable routine to execute with the crafted data, resulting in memory corruption.

Generated by OpenCVE AI on September 21, 2026 at 04:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply:53467 to patch libtiff and the tiff2pdf utility
  • Restrict the execution of tiff2pdf to trusted input only, limiting file permissions or sandboxing the application
  • Audit services that invoke tiff2pdf and enforce strict validation or disable the feature if it is not required

Generated by OpenCVE AI on September 21, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Title Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough
First Time appeared Redhat
Redhat ceph Storage
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-122
CPEs cpe:/a:redhat:ceph_storage:4
cpe:/a:redhat:ceph_storage:6
cpe:/a:redhat:ceph_storage:7
cpe:/a:redhat:ceph_storage:8
cpe:/a:redhat:ceph_storage:9
cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat ceph Storage
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H'}


Subscriptions

Redhat Ceph Storage Enterprise Linux Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-11T17:56:57.498Z

Reserved: 2026-07-31T15:34:43.453Z

Link: CVE-2026-18495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T18:16:56.690

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-18495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow