RHSA-2026:42668: Important: libtiff security update
Important: libtiff security update
Other sources
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.Security Fix(es): libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1 - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1 - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1 - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1 - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1 - Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1.aa - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1.aa - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1.aa - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1.aa - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1.aa - Upgrade
Upgrade
redhat/libtiff-toolsto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1 - Upgrade
Upgrade
redhat/libtiff-toolsto a version that resolves this vulnerability.Fixed in 4.4.0-18.el9_8.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:42668?
The severity of RHSA-2026:42668 is classified as high, with a score of 7.
How do I fix RHSA-2026:42668?
To fix RHSA-2026:42668, update the libtiff packages to the latest version provided by Red Hat.
What vulnerability does RHSA-2026:42668 address?
RHSA-2026:42668 addresses a heap-based buffer overflow vulnerability in the libtiff library, specifically via crafted PixarLog-compressed TIFF images.
What systems are affected by RHSA-2026:42668?
RHSA-2026:42668 affects Red Hat Enterprise Linux for x86_64 and its associated libtiff packages.
Is there a known exploit for RHSA-2026:42668?
Yes, the buffer overflow vulnerability in RHSA-2026:42668 can be exploited through specially crafted TIFF images.