RHSA-2026:54638: Important: compat-libtiff3 security update
The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.Security Fix(es): libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/compat-libtiff3to a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_8.3 - Upgrade
Upgrade
redhat/compat-libtiff3-debuginfoto a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_8.3 - Upgrade
Upgrade
redhat/compat-libtiff3-debugsourceto a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_8.3
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54638?
The severity of RHSA-2026:54638 is classified as important.
How do I fix RHSA-2026:54638?
To fix RHSA-2026:54638, you should update the compat-libtiff3 package to the latest version provided by Red Hat.
What type of vulnerability is addressed in RHSA-2026:54638?
RHSA-2026:54638 addresses a heap-based buffer overflow vulnerability found in the libtiff library.
What software components are affected by RHSA-2026:54638?
The affected software components include redhat/compat-libtiff3, redhat/compat-libtiff3-debuginfo, and redhat/compat-libtiff3-debugsource.
When was RHSA-2026:54638 published?
RHSA-2026:54638 was published on August 13, 2026.