RHSA-2026:49671: Important: libtiff security, bug fix, and enhancement update
Important: libtiff security, bug fix, and enhancement update
Other sources
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.Security Fix(es): libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM (CVE-2023-52355) libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) Bug Fix(es) and Enhancement(s): Reintroduce the tiffcp -i option [rhel-10.0.z] (JIRA:RHEL-185417) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4 - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4 - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4 - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4 - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4 - Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4.aa - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4.aa - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4.aa - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4.aa - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4.aa - Upgrade
Upgrade
redhat/libtiff-toolsto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4 - Upgrade
Upgrade
redhat/libtiff-toolsto a version that resolves this vulnerability.Fixed in 4.6.0-6.el10_0.4.aa - Upgrade
Upgrade
libtiffto a version that resolves this vulnerability.Patch CVE-2026-12912 - Upgrade
Upgrade
libtiffto a version that resolves this vulnerability.Patch CVE-2023-52355 - Configuration
Reintroduce the `tiffcp -i` option as specified for [rhel-10.0.z] (JIRA:RHEL-185417).
tiffcp -i option = reintroduce
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49671?
The severity of RHSA-2026:49671 is classified as high with a score of 7.
How do I fix RHSA-2026:49671?
To fix RHSA-2026:49671, ensure that you update the libtiff packages to the latest version provided by Red Hat.
What security issues are addressed in RHSA-2026:49671?
RHSA-2026:49671 addresses security issues related to buffer overflow and potential out-of-memory conditions in libtiff.
What software is affected by RHSA-2026:49671?
The affected software includes various libtiff packages such as redhat/libtiff, redhat/libtiff-debuginfo, and others.
What does RHSA-2026:49671 include besides security fixes?
Besides security fixes, RHSA-2026:49671 includes bug fixes and enhancements for the libtiff packages.