CVE-2026-35591: Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile
libvips is a fast image processing library with low memory needs. The tiffload operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libvipsto a version that resolves this vulnerability.Fixed in 8.18.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35591?
CVE-2026-35591 has a high severity rating of 7.
How can I fix CVE-2026-35591?
To fix CVE-2026-35591, upgrade libvips to version 8.18.2 or later.
What is the risk associated with CVE-2026-35591?
The risk associated with CVE-2026-35591 is rated at 61, indicating a significant potential impact.
What types of images are affected by CVE-2026-35591?
CVE-2026-35591 affects TIFF images that contain JPEG or JPEG2000-encoded tiles.
What exploit does CVE-2026-35591 pose?
CVE-2026-35591 poses a potential buffer overflow vulnerability when processing certain TIFF images.