Description
OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c and _openslide_tiff_read_tile() to request a full-height destination for a partial bottom tile row, allowing uninitialized heap memory to enter pixel data returned by openslide_read_region(). A crafted but valid slide can trigger the issue in TIFF-based formats other than Hamamatsu NDPI when a network service renders attacker-provided slides. Successful extraction depends on pixel transparency handling and recompression, OpenSlide with libtiff 4.7.0 or earlier is not affected, and official binary builds 4.0.0.10 and 4.0.0.11 are affected. This issue is fixed in OpenSlide 4.0.1 and official binary build 4.0.0.12.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Uninitialized memory exposure in image data resulting in potential information disclosure
Action: Immediate Patch
AI Analysis

Impact

OpenSlide is a C library used to read whole slide image files. A change in libtiff 4.7.1 causes the openslide_read_region() routine to request a full‑height destination for a partial bottom tile row in certain TIFF formats, allowing uninitialized heap memory to be returned as pixel data. The memory content that leaks depends on pixel transparency handling and recompression; if an attacker supplies a crafted but valid slide, the uninitialized data can be extracted.

Affected Systems

The vulnerability affects OpenSlide library builds prior to version 4.0.1. Specifically, the official binary builds 4.0.0.10 and 4.0.0.11, which bundle libtiff 4.7.1, are impacted. OpenSlide 4.0.0.12 and later, as well as any builds that use libtiff versions earlier than 4.7.1, are not affected.

Risk and Exploitability

The CVSS score of 5.3 places this as a medium severity issue, but the EPSS score of <1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a specially crafted slide to a service that renders slides via OpenSlide; thus the likely attack vector is a network service that accepts external slide data. If successful, the exposed uninitialized memory could leak sensitive information from the host process.

Generated by OpenCVE AI on September 19, 2026 at 01:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to OpenSlide 4.0.1 or newer, including all official binary builds 4.0.0.12 and later.
  • Ensure the system does not link against libtiff 4.7.1; use an earlier, unaffected libtiff release or downgrade the library.
  • If upgrading immediately is impossible, restrict the service from rendering untrusted slide files until a patched version is available or explicitly disable support for TIFF formats until the vulnerability is mitigated.

Generated by OpenCVE AI on September 19, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Openslide
Openslide openslide
Vendors & Products Openslide
Openslide openslide

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c and _openslide_tiff_read_tile() to request a full-height destination for a partial bottom tile row, allowing uninitialized heap memory to enter pixel data returned by openslide_read_region(). A crafted but valid slide can trigger the issue in TIFF-based formats other than Hamamatsu NDPI when a network service renders attacker-provided slides. Successful extraction depends on pixel transparency handling and recompression, OpenSlide with libtiff 4.7.0 or earlier is not affected, and official binary builds 4.0.0.10 and 4.0.0.11 are affected. This issue is fixed in OpenSlide 4.0.1 and official binary build 4.0.0.12.
Title OpenSlide: openslide_read_region() returns uninitialized memory with libtiff 4.7.1
Weaknesses CWE-758
CWE-908
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openslide Openslide
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:06:41.600Z

Reserved: 2026-06-15T19:45:23.540Z

Link: CVE-2026-54604

cve-icon Vulnrichment

Updated: 2026-09-18T20:06:37.749Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T21:17:17.000

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-54604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-758

    Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

  • CWE-908

    Use of Uninitialized Resource