RHSA-2026:54640: Important: compat-libtiff3 security update
Important: compat-libtiff3 security update
Other sources
The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff.Security Fix(es): libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/compat-libtiff3to a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_6.3 - Upgrade
Upgrade
redhat/compat-libtiff3-debuginfoto a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_6.3 - Upgrade
Upgrade
redhat/compat-libtiff3-debugsourceto a version that resolves this vulnerability.Fixed in 3.9.4-13.el8_6.3 - Compensating control
Use the compat-libtiff3 security update only if you are unable to use the current libtiff package/version.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54640?
The severity of RHSA-2026:54640 is classified as high with a score of 7.
What security risks are associated with RHSA-2026:54640?
RHSA-2026:54640 addresses a buffer overflow vulnerability in the compat-libtiff3 package.
How do I fix RHSA-2026:54640?
To fix RHSA-2026:54640, you should update to the latest version of the compat-libtiff3 package provided by Red Hat.
Who is affected by RHSA-2026:54640?
RHSA-2026:54640 affects users of Red Hat Enterprise Linux who are utilizing the compat-libtiff3 package.
Is compat-libtiff3 still recommended for use after RHSA-2026:54640?
Compat-libtiff3 should only be used if you are unable to upgrade to the current version of the libtiff library.