RHSA-2026:54642: Important: compat-libtiff3 security update
Important: compat-libtiff3 security update
Other sources
The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.Security Fix(es): libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/compat-libtiff3to a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_4.3 - Upgrade
Upgrade
redhat/compat-libtiff3-debuginfoto a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_4.3 - Upgrade
Upgrade
redhat/compat-libtiff3-debugsourceto a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_4.3
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54642?
The severity of RHSA-2026:54642 is rated as high with a score of 7.
What is the risk associated with RHSA-2026:54642?
The risk level associated with RHSA-2026:54642 is 33.
How do I fix RHSA-2026:54642?
To fix RHSA-2026:54642, update to the latest version of the compat-libtiff3 package provided by Red Hat.
What type of vulnerability is addressed in RHSA-2026:54642?
RHSA-2026:54642 addresses a buffer overflow vulnerability in the compat-libtiff3 package.
Who should apply the RHSA-2026:54642 security update?
The RHSA-2026:54642 security update should be applied by users of Red Hat Enterprise Linux who are using the compat-libtiff3 package.