RHSA-2026:47184: Important: libtiff security update
Important: libtiff security update
Other sources
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.Security Fix(es): libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10 - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10 - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10 - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10 - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10 - Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10.aa - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10.aa - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10.aa - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10.aa - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10.aa - Upgrade
Upgrade
redhat/libtiff-toolsto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10 - Upgrade
Upgrade
redhat/libtiff-toolsto a version that resolves this vulnerability.Fixed in 4.0.9-38.el8_10.aa - Compensating control
Apply the Red Hat libtiff security update referenced by the advisory link (access.redhat.com/articles/11258) to address the heap-based buffer overflow in libtiff via crafted PixarLog-compressed TIFF images (CVE-2026-12912).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:47184?
The severity of RHSA-2026:47184 is classified as high with a score of 7.
What does RHSA-2026:47184 impact?
RHSA-2026:47184 impacts multiple versions of Red Hat Enterprise Linux, including those for ARM 64, x86_64, and IBM z Systems.
What type of update is included in RHSA-2026:47184?
RHSA-2026:47184 includes an important security update for the libtiff library.
How do I fix RHSA-2026:47184?
To fix RHSA-2026:47184, you should apply the latest available updates for your specific Red Hat Enterprise Linux version.
When was RHSA-2026:47184 published?
RHSA-2026:47184 was published on July 28, 2026.