RHSA-2026:58553: Important: libtiff security update
Important: libtiff security update
Other sources
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.Security Fix(es): libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.0.9-29.el8_8.3 - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-29.el8_8.3 - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.0.9-29.el8_8.3 - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.0.9-29.el8_8.3 - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.0.9-29.el8_8.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-12912 - Compensating control
If updating is not immediately possible, mitigate exposure by preventing untrusted users/systems from providing or accessing TIFF files that could be processed (especially crafted PixarLog-compressed TIFF images).
Event History
Frequently Asked Questions
Which systems are covered by this update?
The advisory applies to Red Hat Enterprise Linux offerings for x86_64 Extended Life Cycle Long Life, x86_64 Update Services for SAP Solutions, Red Hat Enterprise Linux Server TUS, and Power LE Update Services for SAP Solutions.
What type of vulnerability does this update address?
The issue is classified as a buffer overflow in libtiff and is rated Important, with a high severity score of 7.
When was this advisory published?
The advisory was published and last modified on 2026-08-24.