CVE-2025-61143: Null Pointer Dereference
Last updated 19 August 2026
Other sources
libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tifopen.c.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.7.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61143?
CVE-2025-61143 has been rated as a moderate severity vulnerability due to the potential for application crashes.
How do I fix CVE-2025-61143?
To fix CVE-2025-61143, update to libtiff version 4.7.2 or later where the issue has been patched.
Which versions of libtiff are affected by CVE-2025-61143?
CVE-2025-61143 affects libtiff versions up to and including 4.7.1.
What type of vulnerability is CVE-2025-61143?
CVE-2025-61143 is classified as a NULL pointer dereference vulnerability.
What are the potential consequences of CVE-2025-61143?
Exploitation of CVE-2025-61143 may lead to crashes or denial of service in applications using affected versions of libtiff.