RHSA-2026:58554: Important: libtiff security update
Important: libtiff security update
Other sources
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.Security Fix(es): libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6 - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6 - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6 - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6 - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6 - Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6.aa - Upgrade
Upgrade
redhat/libtiff-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6.aa - Upgrade
Upgrade
redhat/libtiff-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6.aa - Upgrade
Upgrade
redhat/libtiff-develto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6.aa - Upgrade
Upgrade
redhat/libtiff-tools-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-8.el9_2.6.aa - Compensating control
Update/patch the libtiff packages to remediate the heap-based buffer overflow in libtiff (CVE-2026-12912) caused by a crafted PixarLog-compressed TIFF image.
Event History
Frequently Asked Questions
What input is required to trigger this vulnerability?
An attacker would need to provide or cause processing of a crafted TIFF image that uses PixarLog compression. The flaw is a heap-based buffer overflow in libtiff.
Which Red Hat environments are identified as affected by this advisory?
The advisory lists Red Hat Enterprise Linux for ARM 64 Extended Life Cycle, Red Hat Enterprise Linux Server for Power LE Update Services for SAP Solutions, and Red Hat Enterprise Linux Server AUS. It also identifies the libtiff runtime, development, debug, and tools-related packages.
What should administrators do to remediate the issue?
Apply the update provided by RHSA-2026:58554. The advisory directs administrators to Red Hat's update instructions for applying the included changes.