Description
A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption. | |
| Title | Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough | |
| First Time appeared |
Redhat
Redhat ceph Storage Redhat enterprise Linux Redhat hummingbird |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:/a:redhat:ceph_storage:4 cpe:/a:redhat:ceph_storage:6 cpe:/a:redhat:ceph_storage:7 cpe:/a:redhat:ceph_storage:8 cpe:/a:redhat:ceph_storage:9 cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat ceph Storage Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-11T17:56:57.498Z
Reserved: 2026-07-31T15:34:43.453Z
Link: CVE-2026-18495
No data.
Status : Received
Published: 2026-09-11T18:16:56.690
Modified: 2026-09-11T18:16:56.690
Link: CVE-2026-18495
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-122
Heap-based Buffer Overflow