ALSA-2026:41892
Dashboard / Vulnerabilities / ALSA-2026:41892
ALSA-2026:41892
Summary: Important: libtiff security, bug fix, and enhancement update
Details: The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM (CVE-2023-52355) * libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) Bug Fix(es) and Enhancement(s): * Reintroduce the `tiffcp -i` option (JIRA:AlmaLinux-185328) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2026:41892, https://access.redhat.com/security/cve/CVE-2023-52355, https://access.redhat.com/security/cve/CVE-2026-12912, https://bugzilla.redhat.com/2251326, https://bugzilla.redhat.com/2492871, https://errata.almalinux.org/10/ALSA-2026-41892.html
Affected packages
Package
Name: libtiff
Purl: pkg:rpm/almalinux/libtiff
Affected ranges
Type: ECOSYSTEM
Events:
